I am not sure. It would make no sense for a user to have both tokens. So if they qualified for a user access token then they should get that one over the login token.
I don't know what happens if you try to allocate a 2nd token to a user. You could test it by trying to do it manually in the QMC and see if Qlik Sense would even allow that. If it will not let you do it there then I would assume that it would not do it through the UDC.
Worst case you try it with the user that is in both groups and see what happens. If they do get both it will not hurt anything.