“Domain Group and Members” report is not providing accurate information. Upon review, we noticed that the report does not display all groups present in Active Directory, especially those containing disabled user accounts.
Resolution/Workaround:
Provide the Domain admin level permission to service account and run the discovery.
After discovery finishes successfully, disable user accounts information shows correctly.
BUGs to improve AD discovery related to this issue:
Improve UI warning when failed to collect some user attributes -> BUG ID: 612870
AccountIsDisabled not correctly stored in ER Database if discovery credential lacks permission to read property -> BUG ID: 612883