Mark Russinovich of sysinternals fame, an author I have a great deal of time for, has published a fascinating blog describing a proof-of-concept application called GPDisable which, when allowed to run, can circumvent parts of group policy - it even works