Everyone might already be aware, but I saw today in testing that an Active Directory bind object created in the Casper Admin Web interface, logs the password of the account used to bind to AD in clear text to the secure log on the client during the first run script.
Be very careful what account you are using to create the object~!
(And maybe add an additional policy to remove this log after binding).