The SQL errors appear every 5 minutes while the "Microsoft Azure AD Sync" running, and there are always two each time, with the below messages:
Login failed for user 'DOMAIN\MACHINE$'. Reason: Could not find a login matching the name provided. [CLIENT: IP ADDRESS]
and
Error: 18456, Severity: 14, State: 5.
To clarify, I do not believe this is an issue of permissions or configuration, as Azure AD Connect appears to be working correctly using the gMSA (i.e. accounts are being sync'ed and the database is being updated). The issue is that it is also, in addition and not as configured, attempting to connect to the SQL instance using the machine account as well. The machine account doesn't have access to SQL, so the error is a legitimate refusal. It is the authentication attempt that is made in error.
This seems like a bug to me. Have you encountered it before?