the current planning is to get user/groups done first, obviously, thats the part where most of the security will be involved as well.
do you have any knowledge on that?
what we want for the business core is a strict dividing line between user and administrator.
This is mostly OS security, and that I don't do.
For example, as I have mentioned, I have an NT domain here. I have had it since NT 3.1 shipped, but only had some 'real' clients after I upgraded to NT4.
I have 2 users with admin level authority. My ID and my wife's. The kids are just users. (the boys abusers?

). I regularly use the hidden shares C$ and D$ to make my life easier to look at everyone's home directory and the apps directories.
What would be the equivalent to C$? /home, I would think. How would I create a share for /home that only selected users have R/W privileges to. And would that even work with the way Unix permissions go?
I guess the first step is for two groups: Admin and Users. Can you set up common shares so that both have access? I don't know. This is OS security.
Now if you are talking about ways to secure NetBios traffic over IPsec and/or HIP. That I can look into....