You only will need to scan the user with user domain scanning and then also the groups where he belongs to will be scanned. Also if the group is located in another OU.
You can use the following report:
Select Top 1000000 tblADusers.Username,
tblADusers.Userdomain,
tblADGroups.Name,
tblADGroups.Description
From tblADGroups
Inner Join tblADMembership On tblADMembership.ParentAdObjectID =
tblADGroups.ADObjectID
Inner Join tblADusers
On tblADusers.ADObjectID = tblADMembership.ChildAdObjectID
To use the report above, do the following:
• Open the report builder under Reports/Create New Report.
• Paste the SQL code we provided at the bottom of the page.
• Left-click somewhere in the upper section of the page so the code applies.
• Give the report a Title and hit the Save & Run button to save it. Export options are listed on the left.