Is there a way to configure LS to scan all the users & computers in AD since, technically, AD is my source authority to what users and computers I should physically have?
However, at the same time, I want to use LS to scan everything, like systems or people that someone plugs into my network.
How do I separate the two for audit purposes when reporting what should vs what I see with added unknown systems?
Yes, you can configure Lansweeper Active Directory to scan your users and computers. The following article will provide a guide on how to configure Domain Scanning. https://community.lansweeper.com/t5/scanning-your-network/scan-an-active-directory-domain-scanning-t... After this, it should only scan the computers that are available on the Active Directory, and you could set up an IP Range target to scan for any other devices connected to the environment. This will allow you to review which devices are connected and review any new ones that have been connected in the Last 24 hours by using reports such as the following: https://www.lansweeper.com/resources/report/hardware/new-devices-found-in-the-last-24-hours-audit/