I've followed Provogeeks example with out an AD or Domain structure in place. I have had people that do not create the DLU users as local administrators, and then start getting strange messages in login scripts, and problems with install apps. Looking on Novell's cool solutions site, reccommends using at the very least Power User, but would prefer Administrators.
In the areas where there is a Domain, however, we have turned DLU off for those specific users, then created a couple of application objects that basicly run a couple of scripts to join the domains. Not a very clean method, but it has been working.
I understand that with the latest service pack to Zen4, there is another option in the DLU policy to help work with Domain authentication, but have not had a chance to work with it to see exactly how it works.
Can't stress enough on how much work can be put into the group policies. Just when my company thought we had them locked down enough, something would stop working.