Howard, I would like to run it from the login script. Users will have admin rights.

Shelling out net localgroup administrators would be a possible solution, but it doesn't differentiate between users and groups as members. It just spits out everything.