Thanks. Yeah, I've been looking at the Group Policy MMC, and I noticed that Add/Remove Program policy. Also, if I configure the "Run only allowed windows applications" policy under User Configuration->System for, say, a user account with admin privileges, then he/she will not be able to execute any programs that I haven't specified, correct (even if that person installs a program I didn't specify)? In addition, does altering a user (with admin privileges)'s policies effectively negate admin privileges (i.e. the ability to allow Anti-Virus and Critical Updates to install)?
One last thing, I thought setting Automatic Updates in the Security Center (forgot to mention the machine will be running XP Pro SP2) only downloads the updates and then makes the yellow shield appear in the system tray. Doesn't the user have to manually confirm the installation of the updates?