Hi,
You can create a group for each server using the following command:
Get-ADComputer -Server contoso.com -Filter {(Enabled -eq $true) -and (OperatingSystem -like '*Server*')} | Foreach{ New-ADGroup -Name "$($_.Name)_Administrators" -SamAccountName "$($_.Name)_Administrators" -Description "Administrator Access for $($_.Name)" -Path "OU=Groups -SVRAccess,OU=Role Based Access,OU=Groups,DC=contoso,DC=com" -GroupCategory Security -GroupScope DomainLocal }
You can create a schedule task if you want create this group automatically for new joined server.
Then you can use group policy preference to add this group on each server:
On the setting above , you can also delete all users and groups and let only allowed groups.
To get more details you can refer to the following link :
Using Group Policy Preferences to Manage the Local Administrator Group
Please don't forget to mark helpful reply as answer