Quote:

A start-up script GPO is also an option.



Now that would be a bit of a challenge to modify the users hives! If you can do a GPO startup script, then why not just use GPO directly to deploy the policy?

I don't get why Shawn said he needed custom ADM templates. The standard GPO templates allow for the "Import" of Security zone settings. I know cuz I use them. I also self-sign certs and use a GPO to push out myself as a root cert authority.

I dislike seeing policy reg hacks in KiX. First off, that is what GPOs are for. Second, users can read through the script and figure out the reg hacks and reverse them.
_________________________
Give a man a fish and he will be back for more. Slap him with a fish and he will go away forever.