There's nothing built-in to UEM to do that remotely. However, you should be able to use something like psexec or PowerShell for that, as long as you have the correct permissions in place. Beware that when you assign anything to a user using an AD group that the member wasn't a member of during the initial logon. The user still requires to logoff and logon to refresh AD group membership (token).
\\ Ivan
---
Twitter: @ivandemes
Blog: https://www.ivandemes.com