Resolved! does the service account that scan domain controllers need to have Domain access permission?
Do we need the service account that scan domain controllers to have domain access permission? can they still be discovered if we just give them regular admin not domain access? is there a documentation for it?