Security has been applied with a service account on the Configuration context, and Default naming context as recommended by Quest. Therefore the service account does not need to be a member of Enterprise Admins. Service account is also a local Administrator of the GPO Admin server.
When installing GPO Admin as the service account in an environment with ActiveRoles Server installed, the error occurs: Unable to create Service Connection Point.
Access Template may be in place to restrict the service account applying Service Control Point (SCP) to the computer object in Active directory.
Open Active Directory Users and computers.
Select view -> Select "advanced features"
Navigate to the computer account for the GPO Admin server.
Right click the computer account -> Properties.
Select the "security" tab.
Click on "advanced" -> Select "Add"
Enter the GPO Admin service account and click OK.
Add permissions to "Create child objects" make sure that this applies to "this object and descendant objects".
Select "OK" -> "OK" -> "OK".
You will now be able to run the installation again which will have permission to install the Service Connection Point.