we are limited on group memberships allowed to be created on the local workstation...though this is something to consider. This would cause the logon script to double check the user at each logon. If they are approved a device and later the device is revoked, the logon script will have to remove the user from the group.
_________________________
John
LM Contractor
One of the 2 dads