Earlier quoted context omitted.
>Isn't the automatic reaction of a Windows desktop/laptop user to lock their workstation Having attempted to encourage this as a habit for my users for about a year, and not a single one doing it, I've had to come up with other solutions that takes it out of their hands. (It's not business-critical for us, however we try to encourage good security habits all around). So no, I don't think it is an automatic reaction f…
So what you do is take a screenshot of whatever's open on their computer, close it, then set the screenshot as their desktop wallpaper. Also hide their icons for good measure. This should start a cycle of escalation and retaliation that eventually gets the whole office locking their PCs.
We weighed our options and decided that it was a battle we would rather not waste our effort and risk staff animosity with. When a more serious security incident occurs, or when we decide to implement something else that may require staff effort, we believe that our staff will be more willing to work with us towards a solution.
Sometimes with security policy, a little give (proportional to risk analysis) can go a long way with non-technical staff. I'd rather work with staff to come up with processes that work for both the security staff and all other staff members than become so rigid in my security policy that I may inadvertently alienate the security staff - which has many risks itself.