Luke, You are right, if the client is not in AD, then no GPO to turn on the NAP agents. If that is the case then the machine with be quarantined. The servers that are part of your remediation group will allow those machines to be joined to the domain (you have a RODC there) your DHCP server will still server the client an address, just will only allow routes to the servers in the remediation group. Once there you can join the machine to the domain and it can recieve the GPO. For future use, i would suggest turning on the NAP agents during an unattended build process, that way the GPO is only a fail back incase someone tries to turn of the agents.