No - not the point...
1. You create your admin account in AD, NOT a member of domain admins.
2. You create a group called Computer Admins, make your account a member of that group.
(in larger organizations, you also create Workstation Admins and Server Admins to split the authority across groups/teams.)
3. You make the Computer Admins group a member of every local system's Administrators group.
When you log in, you have admin access to manage computers, without being a DOMAIN admin. You can assign your account permissions to create/unlock accounts and reset passwords as well, so you can do 96% of admin work without exposing all the rights to AD. You log in with the domain admin account only when making changes to AD itself - OU structure, GPO, etc.
Glenn
_________________________
Actually I
am a Rocket Scientist!