You can use restricted group feature in GPO for this.
Please refer to following link for more detail:
On 10/27/06, Danny <[EMAIL PROTECTED]> wrote:
Looking for ideas on how to provide a domain administrator in a separate forest local administrator rights on all domain computers to assist with ADMT v3 computer migration.
Thanks,
...D