A domain user account is required to provide a network identity for AD RMS so that it can communicate with other services ...

A domain user account is required to provide a network identity for AD RMS so that it can communicate with other services on this computer and the network. The domain account should be a standard domain user account with no additional permissions.  Specify the account under which the AD RMS cluster will run. The AD RMS service account will be a member of the AD RMS service group and will have the permissions defined for that group.