The issue is that you should not have a file that contains commands that will run with elevated Privileges residing on the local box (imho)

It is quite simple to run the BIOS and change (unless you have also password protected the BIOS, but that too could be problematic for you as an Admin when you or other support personnel need to work on it). You can also boot from USB devices now days as well.

Bottom line is that when ever possible it is better to keep as much as possible off of the local box that contains control features.
Use GPO when and where possible, you can force GPO refresh as well if needed.

Or at the very least keep the control file on a server where you have control of it at all times.