Thanks Vortexx. Your post was the exact solution I needed. It follows from this article at Microsoft (932163,
Method 1) but still leaves the computer connected to the domain (a much better overall result from an infrastructure management perspective).
I've also asked Microsoft to indicate which GPO's are likely to cause this kind of failure (I'm not holding my breath, baesd on the fact that it's a consumer product). Ah well...