Microsoft's Baseline Security Analyzer (MBSA) is also a useful tool. It's helpful for determining server and workstation configurations remotely. You can take a sample of each and see if they are lacking patches, updates, or have holes such as enabled guest accounts.
_________________________
Everyone has to make a living, mine just happens to involve thumbscrews.