It's a bit more work but a more useful long-term solution is to create a group in AD called something like Local_Admin_PCName, then add that to the PCName\Administrators local group. This makes it easy to manage centrally and allows more than one local admin. For instance, most PCs might have a group called Tech_Support_Staff as a member.