Cake will find it extremely difficult if not impossible to diagnose what areas of the registry do have permission and what areas don't I would suggest if the user permissions are restricted, if a user is restricted then they are restricted. GPO is a complex affair. It would be a guessing game unless the user wants to install the GPO tools and go through all the options to see what works and see what doesn't (could take all day)...
Unless I'm barking up the wrong tree... Cake may find it is something entirely different.
But Ross has already stated he has had "special permissions" revoked on his hard drive (and even then I'm not sure which areas), and special permissions is just a subset of any file permission + a load of other file permissions thrown on top, and the registry (GPO) this is anybody's guess especially if Ross will be locked out (otherwise administrators would not have restricted him). Smells like a smoking gun to me.
End of the day, no sudo, then it is no sudo.... (not to be confused with Run As Administrator which is something similar but very different)