how about "simple" remoteexec on those machines that calls "net localgroup add" with the admin user credentials...