A startup script gets run (from a Domain Controllers point of view) using the 'Domain Computers' Security Group. You can then put the script on a share / a folder and lock it down using NTFS so only domain computers have read only access to this share/folder. Then, if a user knew the path to the script (not hard to get via RSOP.msc) they wouldnt have NTFS permssions to view anything in the folder.

Edited by lukeod (2008-12-15 01:07 AM)