    gmiley wrote:
     As long as you have someone that knows how to manage MS networks you should never have to log in as an administrator.

    That's the problem right there. Most companies dont have people that are actually certified ( or have even read a book) on domain / AD adminstration and the users are the ones who end up suffering.

    I always add my domain account to the local admin group as soon as I get a new pc. It's the only way I can actually get around the badly designed domain policies and get my work done.