Howard,
That sounds like a good method. What process (via logon script) are you using to log machines that are not compliant? That sounds like something management might go for..

Brian