Eric_Vernon: Great stuff.
Like will nimmo I'd be interested to know if this is a thing that will impact the server OS where the criticality is often a bigger deal. Though you could argue that on the server side there's probably less of a chance that a non-security update breaks critical functionality.
The other feedback I'd give is KIR GPO bloat. I can promise you that most orgs are just going to add a KIR to the policy and never think of it again. While on the individual level that's probably not a huge problem, if each KIR is it's own policy/whatever that you're publishing then overtime that's going to create bloat that will impact GPO processing times. GPO is the poster child for 'set it and forget it' until a new admin comes in and asks what these 2000 policies do and why they were set.