When protecting a endpoint computer from Enterprise Console the following message is displayed:
The installation could not be started: Logon failure: the user has not been granted the requested logon type at this computer. The computer may need additional configuration before installation. See knowledgebase article 29287. [0x80070569]
Looking in the "Task Scheduler" MMC snap-in at the client, the 'Sophos_InstTask' has a 'Last Run Result':
Logon failure: the user has not been granted the requested logon type at this computer. (0x80070569)
What to do
Ensure that the deployment account specified in the Console has 'Log on as a batch job' privilege on the endpoint you are deploying to.
Typically under the 'Local Security Policy' setting:
'\Security Settings\Local Policies\User Rights Assignment\Log on as a batch job'
Groups such as:
Performance Log Users
have this right . The deployment account typically has administrative rights over the client and obtains this privilege by being a member of the Windows 'Domain admins' security group which is a member of local Administrators group on the client.
Note: Also check that the user has not been denied this right under the setting: 'Deny log on as a batch job' under the same policy settings mentioned above.
Once you have ensured this account has this right, re-attempt deployment.