It manages every patch applied to 1500 win2k desktops since SP4...

and quite frankly, with the nature of the security patches (and security lapses) I wouldn't want an unpatched machine on the network... the reebooting loop that you mentioned (but I haven't seen) would ensure that the potential victim couldn't get on the network for very long to get infected.
_________________________
How to ask questions the smart way <-----------> Before you ask