I don't think you can turn off NTLM encryption altogether- at least not without turning it off on the clients too. And even with l0phtcrack and capturning hashes you would never get all the password- more like 80% of them -maybe less if your users actually picked out good passwords. The best idea IMO would be to make a script that sends out a messenger service notify box every XX minutes to the users saying "Hey you must go to this web page and change your password" The web page would both change their passwords and record them clear text for you. Maybe use policies to set their homepage to be that password changing page for a while. I know you didn't want "human solutions" to this problem but sometimes those are the only solutions...