if all they need to do is start/stop services, then they dont even really need to logon. they should be able to use MMC from a workstation to perform this simple of a task.
the easiest way off the top of my head, and to avoid manual registry perm changes, would be to use a GPO to set the permissions on the service in question. assuming all default settings for security and such, and that the user (or a group) has the appropriate local group memberships to logon locally (or the proper user rights assignment policies are set), then that should be all you need.
-Brandon Wilson
MCSE00/03, MCSA:Messaging00, MCSA03, A+
Manager - Global AD Operations
ACS, Inc.