I actually wrote this post awhile ago on my blog and forgot to cross post this to the GP blog. Bad me...though I have updated it recently with new information! 🙂
Essentially its the minimum permissions you need to run AGPM without Domain Admins access given to the service account...
Hope this helps!
Michael Kleef, Program Manager, GP