The user running the Application Manager must have access to both the servers' administrative shares and have rights to modify the SPN permissions.
The target's machine account needs to be added to the source's Active Directory computer object for the purpose of updating the SPNs during failover and failback.
The administrative shares are used to manage the configuration files and failover scripts on the source and target. To satisfy both of these rights, it is recommended that the user must be a member of the local Administrators group on each server (source and target).
Follow these steps to add a user to the Administrators group on each server.
Next step: Assign users to the DnsAdmins group