You can also use ACLs and policies to lock down servers - free to use, but you need to know what you're doing.... using a firewall that blocks *.exe, *.com, *.bat, *.cmd etc is probably worthwhile as well.... finally, given that it's Citrix what I'd do is use something like Ghost to image the...