Having just taken over this old network, I have found the following to answer your question Les.

For some unGodly reason the domain admins group was removed when some of these machines were setup. A particular user was added to each machine as a local admin.

We dug up this user name and pw combination a while back and want to use it to set up some very simple settings prior to migrating to AD. After the migration I should be able to do most admin task through GP's but until then, this is my backdoor.

Thanks