IIRC, there's a "boot-time" script option (as opposed to a logon script). the boot-time script should run as SYSTEM, and thus should be exempt from the policy ...