I haven't read all the posts but I think your users are gonna figure out pretty quick how to swap NICs.
I would be looking for a per user login way to do this. Maybe with IE 'trusted zones' or something.
seems to me blacklisting sites by IP address is not getting at the root cause, it's not feeding into the MS domain account way of doing things. I wonder if you would get anywhere emailing MS support with this question...