If you assume the default model for deploying SME as Domain - Server - Workstation; i.e. SME Server as a Domain Controller on a Windows Workgroup, workstations require Ctrl-Alt-Delete to logon
On a Windows Server - You can do stuff to the workstations from the Server using Policies
Prior to Win Vista, you could achieve much the same result with a logon script
And the difference is UAC - User Account Control
I currently struggle through with UAC enabled
So my Questions is - Do you Disable UAC ?