Hmmm some options:
1) Customize a hosts file (c:\windows\system32\drivers\etc\hosts) and push it out by GPO.
2) Implement WebSense (or similar).
3) Get a Firewall (like WatchGuard) that can do WebBlocking (http://www.watchguard.com/products/webblock.asp)
4) Put in a HTTP proxy for all traffic out of your environment and control it that way.


