I am quite certain you are at a crossroads. A client & server crossroads.
In order to do this correctly youll need to have at least two machines.
one runing server 2003 and the client(s) running XP Pro.
Time to get some hardware.
You CAN load both of these OSs onto two different HDs but you will not be able to
run them simultaneously and both will be registered to the same chunk of hardware
which can make for lisc. nightmares.
CDW is always running great deals on IBM tower servers, some not that powerful
but for under 700$ you can get a pretty beefy system that can do the trick.
As for nasties getting into your system I would advise a simple hardware firewall
manageable from inside your networks. LinkSys offers many low cost soloutions
for firewall/routing that also include VPN capability and will allow you to block all kinds
of traffic. you should only require a few ports to be open to surf the web & read email.
I wouldnt allow users anything more than basic priveledges on the
client. They tend to install crap that shouldnt be there and that just
opens you up to a whole slew of vulnerabilities.
Good luck & happy hunting,
Cain