I have a domain account for scanning Active Directory domain computers in Lansweeper for the Global Windows account.  Because this requires local admin privileges, I've put this account in the "protected users" group in Active Directory for additional security.  I've noticed that under Scanning Targets for active scanning it will say invalid credentials.  However, I know the credentials are correct.  If I select a computer asset in Lansweeper and click "rescan asset", it scans the computer with the same Global credentials without issue.  If I remove this account from the Protected Users group, the active scanning under Scanning Targets does not show "invalid credentials".  So why is active scanning different from rescan asset?  Is the only way this works to have the scanning account NOT a part of protected users?