It sounds like you're after the Client Administrator account here, of which you are forced to create at least one, during client package creation. These are accounts that exist within SEE alone, and not within Windows, but that allow authentication past the Pre-Boot Environment, as well as other administrative functions on the client.
This old article discusses how to update and distribute client administrator accounts via GPO and should still be applicable:
http://www.symantec.com/docs/TECH161649
This article shows how to use The Client Administrator account at Pre-Boot:
http://www.symantec.com/docs/HOWTO110298
As the name suggests, this account is for administrative purposes, and is not one I would normally recommend sharing with users. Is that what you were after?