How do y'all handle machines that don't check in? In a large company like ours, we have constant turn over - user's/manager putting former employees machines in their desk drawers until a new employee is hired, lost, stolen, damaged, "borrowed to use at home", or just plain DB glitches - where the machine is here but not talking to the JSS, etc. Most are machines that were deployed prior to our DMZ setup, so they have the internal only JSS setup on them.
I know about Rich's CasperCheck which helps for going forward, but not the backfill.