You cannot restrict an administrator from doing anything on a machine that they have administrator access for.

http://support.microsoft.com/default...;en-us;Q240267


And if you remove the domain admin group from having administrator privileges. They can easily give it back to themselves with the following.

http://support.microsoft.com/default...;en-us;Q297307


I would suggest encrypting the data that you want to keep out of the hands of the domain admins with something like PGP.