For our Lab and Classroom deployments, we create several accounts via policy as part of our deployment, including one that is an auto-login account. The problem that we just discovered is that while we do create a local administrator account, since the auto-login account is the first to actually log into the computer, it is the account receiving the secure token.
Does anyone know of a way - other than disabling auto-login and manually logging in to every computer first - to make sure that our local admin account has the secure token, rather than the generic user we are creating?