Device inventory is not privileged account discovery
A device inventory tells you where the machines are, while a privilege inventory tells you where an attacker can go. An endpoint record can show that a machine exists, who owns it, and whether a management agent has checked in. It does not show who can administer that machine. That distinction matters because an attacker doesn't need a complete asset inventory. A valid privileged path to one useful endpoint may be enough.