The scanning account you use must have administrative permissions on the client machines and must have read only access to active directory.
We recommend a domain admin because this is the easiest way for most customers, but you can choose any account you want.