Hi
I suggest to do this with a Policy instead of using a Script. There you can also configure the "User Rights Asignment" which -as example- gives the remote login permission to the "remote desktop group" itselfe.
<admin: removed echo'd message from below here>