Resolved! User-ID agent 4.1.0 service logon account permissions.
User-ID agent 3.1.0 ran quite happily on our Domain Controller under a regular domain user account (no group membership apart from the default Domain Users, and I guess "Ran as service" was granted automatically during the installation).
The new versi
...