client machines in a domain automatically add domain admins into their local machine admin group. In situations where an enterprise administrator needs access across an entire forest what is the best way to grant this. You cannot add members of a remote domain to the domain admins group. Is there a way around this?