I would like to deploy ICF via a GPO in my win 2k3 AD environment. Is there anyway I can control which users get the ICF installed? Also can I control if ICF gets applied on or off, and perhaps which ports are allowed or not. I would like to control it so I can deploy it to certain laptop users, and give ICF a certain configuration. There are lots of users that have laptops that come in and out, and I want them to have protection on foreign networks they connect to, but not get blocked from resources if they dont turn off the firewall when they hit the LAN. Can ICF do what I want? Is there a better managed solution I should look at?