Domain Controllers and Domain joined computers are picky about permissions. The issue is that the AC installer is geared towards P2P networks and resets the security permissions upon upgrade and adding the Everyone group to the ACL. The way it is declared is what domain controllers don't like. It's a recent "improvement". I would add the permissions for a security group that has the domains users that need to access AC.
If you need help with this, you can PM me.