Active Directory and group policy. Filter the policy to prevent it from applying to administrators. Local policies apply to all users who log on to the computer, so that's not the best option. However, you could define this policy using local policy and then prevent administrators from reading it by changing the ACL (Access Control List) on C: | Windows | System32 | GroupPolicy.
This was first published in January 2003