Hi,
You haven't provided any details on what you mean by access the computer, is this admins or RDP access?
One possible option:
You can use GPO GPP to allocate a delegation group to either administrators, or remote desktop group on the computer to match the access requirements. Then you can add the user to the delegation group to provide access. To simpfy to GPO management and remove the requirement to create a GPO for each delegation group, you can set the group to be assigned in GPP using environment variables %computername%-admin or %computername%-rdp, this way you can have a single policy setting for the all the computers.
Gary.