I understand the process of creating a Tenant Administrator or Self Service User. These roles execute tasks using a Runas account. The Runas account contains the "Active Directory" or local user account. What permissions do the "Active Directory
account" residing inside the Runas account need to be able to create virtual machines on behalf of the self service user? Typical scenario:
Create a user account in an OU in AD. We are planning to use this account inside a Runas in VMM to deploy VMs. On what objects should I add the user account and what permissions does this account need to successfully deply VMs using templates?