George,
That is true, except that the averague user does not know how to access Device Manager, the Command Prompt form the Run Command, do a Print Screen to Paint, etc. Most of the software applications can be hidden well enough to stop the "average" user. Besides, while I suppose I can discipline someone from abusing the Internet policy (although difficult with allowing them some freedoms), they would be in quite a bit of trouble in they uninstalled or changed settings on a program. And, that's the beauty again of a domain. You could completely shut off their ability to use or change a certain application. But, you do raise a very valid point.