News

2) add the group to Local Administrators group on each machine. If a user needs to be removed, you remove them from the group, and no need to touch the machines themselves again.
If you want to do it anyway, why not simply add "domain users" domain group to the local admin group on every computer? You can even script this and be done with it in a couple of minutes.