I think your approach is good, sounds like the "right way" to go about it.

Let me be clear about what you're asking though. You're saying:

- Add a Domain sub-group to a Local Admins group = works.
- Add a Local sub-group to a Local Admins group = fails.

Is that what you're getting?

Next question:
- Do you get this same behavior whether you do the job scriptingly, or by hand from the "Users and Groups" screen in COMPMGMT.MSC? If you haven't tried the latter, try it and see if maybe there are warnings popping up that you don't see in the script.
_________________________
Tony Fabris