What is the effect of adding the local account labadmin to Administrators via Restricted Groups?
labadmin stays (or becomes) a local administrator on every computer the GPO applies to, and survives the authoritative membership reset.
Because Restricted Groups replaces the group membership on each refresh, a local admin account that is not in the list would be thrown out. Listing it keeps a local way in, which is useful if the domain is unreachable or the domain trust of that machine breaks.
The flip side is a security question worth raising in an oral exam: one local account with admin rights on many machines is only safe if its password is different on each one. If it is the same everywhere, cracking it once gives an attacker admin on all of them (lateral movement). Microsoft's answer to that is LAPS, which sets a random, rotating local admin password per machine and stores it in AD.
Go deeper:
Microsoft Learn: Windows LAPS overview — a unique, rotating local admin password per machine.
Wikipedia: Pass the hash — how one reused local admin credential opens many machines.