I've been using a managed service account for the service account that PMP uses for it's local service, with much success I must say. However the way to get it working is to make the msa a member of the local administrators security group. As we try to leverage the concept of "least privilege" as much as possible I would like to know if there's documentation on the user rights etc that are needed to operate PMP on the local box.