Domain administrator account does not have the proper local administrative rights to collect share level ACL's.
The Domain Administrator account is required to collect share level ACL's per Microsoft. However this requirement also assumes that the Domain Administrator account is included in the Local Administrators group on the filer.
Please make sure that the Domain Administrator account used for scanning the share is also a member of the Local Administrators group on filer itself.