LDAP Active directory user permission

I was looking at linking nextcloud into my AD through LDAP. I have a couple of questions.

  1. With the AD account that I specify for nextcloud to access the AD, what permissions does this account require?
  2. Am I correct in that if the nextcloud user changes his or her password in nextcloud it will migrate back to the domain account as well?

This is a support question and please add necessary information from our support template.