IIRC, there's a "boot-time" script option (as opposed to a logon script). the boot-time script should run as SYSTEM, and thus should be exempt from the policy ...
Some users are failing to import registry files. When trying to do the same, an error message saying Cannot import file: The specified file is not a registry script ...