They actually address this in the documentation. "User permissions for AD integration While the AD integration account does not have to be a domain admin, it is usually the easiest way to implement this feature. If using a domain admin account is not possible or not preferable, ensure that the account has the necessary permissions to perform the following actions: Query the user database via LDAP Query group membership via LDAP Query the domain controller via WMI" See here
... View more