We have a recurring problem with laptop users that "accidentally"
remove their machine from the Windows 2000 Active Directory domain.
They always seem to do this while away and then freak out because they
are suddenly locked out of their machine. I know you can create a
local user that will still be there if they do this but I was
wondering if there were other options.

I would like to know if there is a way to prevent them from removing
the machine from the domain in the first place? The simple solution
would be to take away administrators rights, unfortunately they need
to install software so I don't think that is an option.