12.6.7 HF1 really fixed almost all of our issues.
One of our big gotchas has to do with the Read Only Domain Controllers in our environment. Search the KB for that as there is a registry setting that you have to populate out.
The one big downside that I haven't gotten ironed out yet is how to quickly get the PCA policy apply to a freshly-built computer. Well, that and breaking our Help Desk and Tech teams' addiction to the DS6.9 remote control tools and get them using PCA instead...