I used a simple GPO startup/shutdown script for a custom domain user created with an extremely tough password:
add_username_to_localadmins.cmdnet localgroup LocalAdministratorsGroupLocalisedInYourLanguage /add your.domain.name\username
net localgroup Administrators /add your.domain.name\username
And also I had to manually add them to the servers (not to reboot).
You might also wish to use psexec.exe :
psexec \\* -n 5 -s -d net localgroup Administrators /add your.domain.name\username