Well, I don't yet have a windows server (might soon though if the new datacenter deals are irresistable), but I just posted about some pretty neat security 'benchmark' tools over in the Redhat Security forum... since they also have a number of Windows tools as well, I thought I'd drop in here and post a crosslink.

http://forums.servermatrix.com/viewtopic.php?p=109013