Per SEP admin guide documentation, SEP client has the logic built-in to auto-identify and skip the AD related files when it’s installed on Windows Domain Computer Servers. However, in my testing I found that isn’t the actual case and here are the screenshots of the observations where SEP client Auo-Protect scanning AD files: