Let's step back...
- Zone provisioning agent runs as a service account. You can identify the account by looking at the ZPA applet in the system running ZPA.
This account...
- Does does not have to be a privileged account in Active Directory. Just like you said, the AD permissions are granted via the Delegation Wizard for the corresponding zone in Access Manager, based in the description that I gave you above and your design goals.
- On the Windows System it requiresthe local right to "Log on as a Service"
Are you working with Centrify Professional Services or have you been through the Centrify Training or CBTs?
LMK.