Microsoft AD DS domain controllers, Microsoft AD CS CA servers, Microsoft AD FS servers and Microsoft Entra Connect servers are only used for their designed role and no other applications or services are installed, unless they are security related.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.