Thanks, jared_f. Great explanation, as far as I can tell! We are not running AD, so maybe that will hold me back from doing what I want to, but I suppose it's not the end of the world to just allow the end user to create their own local user, etc if I really want the ease of not touching the devices before they're given out.
... View more