The org.freedesktop.realmd.policy file contains invalid policy for remote users. The <allow_any> lines apply to remote sessions, such as admin users logged in via ssh or Cockpit. It doesn't matter how the admin user is logged in, he should be allowed to control the realm identically.
Created attachment 98448 [details] [review] service: Fix desktop-centric polkit policy We should have policy for non-local users (such as logins via ssh or Cockpit).
Attachment 98448 [details] pushed as 69cab4b - service: Fix desktop-centric polkit policy
Use of freedesktop.org services, including Bugzilla, is subject to our Code of Conduct. How we collect and use information is described in our Privacy Policy.