Managing membership of Domain Groups by using Restricted Groups
Microsoft does not support using Restricted Groups in this scenario. Restricted Groups is a client configuration means and cannot be used with Domain Groups. Restricted Groups is designed specifically to work with Local Groups. Domain objects have to be managed within traditional AD tools. Therefore, we do not plan currently to add or support using Restricted Groups as a way to manage Domain Groups.
Точно видел, что это происходит политикой, но не помню локальной или групповой.
Группа администраторы домена имеет SID: S-1-5-21domain-512, политика добавляет этот SID в группу локальных администраторов.
gpresult /H gpreport.html
И посмотреть что приходит в конфигурации компьютера Administrators: Members of this group have full control of the server and can assign user rights and access control permissions to users as necessary. The Administrator account is also a default member. When this server is joined to a domain, the Domain Admins group is automatically added to this group. Because this group has full control of the server, add users with caution.