Thanks, spy, that pointed me in the right direction. I'm forgetting - being a *nix guy - that groups can be included in groups. Checking out the (local) Administrators group on the client machine shows that (local user) Administrator and (domain group) Domain Admins are members. Not Enterprise Admins, though... wasn't that supposed to have the highest privileges? These are default installs - this is just a test network at my place - so no group policies or anything yet.
In any event, adding myself to the Domain Admins group takes care of it. Only after a reboot, though - does the client cache authentication info or something?