Wow!
Trevor,
ever heard of repackaging?
http://www.wisesolutions.com/Products/Packaging/Overview.aspx
In another life i used to repackage apps and one of the most important things was NOTHING runs with admin privileges. If it needed it, we would work with the vendor to fix it or dump it for something else that doesn't. Granted, this was quite some time ago and badly written apps are now common place in the enterprise COTS software world. :-(
I don't agree about re-imaging workstations monthly. If your QA process is questionable or non-existent and if something goes south, keep your resume up to date!
There was someone who mentioned wireless connectivity on laptops outside of the managed environment as a reason to be admin. Sorry, wrong get a better supplicant like Juniper's Odyssey.
There was another comment about Power Users and regular users or something to that affect. Sorry, there is only one class of "user" not developing or administrating, that's "L"users and they will F!@# up a paperweight if given enough time and permissions.
I will say this very very slow for everyone who lets their users install software on corporate managed infrastructure.
U-N-D-E-R
N-O
C-I-R-C-U-M-S-T-A-N-C-E-S
D-O
U-S-E-R-S
I-N-S-T-A-L-L
S-O-F-T-W-A-R-E
P-E-R-I-O-D
If you allow them to you do not have a managed network, you have a bunch of home PCs all plugged in and accessing your IP. You introduce so many risks to the organization the el' Reg comment box would puke if i tried to list them all. Here are some highlights though,
Licensing, Incompatibility, Internal Support costs, Security, Privacy and on and on and on
Albeit, if you don't have the $$ to fully manage your infrastructure you are bailing at best. I do feel for you and ultimately security and stability have to make concessions to reality. :-( Not a good place to be but you can befriend a CISSP ;-)