We have created a Domain Service account (SA_COR_JIRASD) Used by Jira to read attributes for user accounts and groups in AD. it is also a member of Domain Admins, we would like to remove it from Domain Admin group but still allow this service account the access to read user account and groups in AD. Is this doable and if so, what access rights would the service account need?