https://support.microsoft.com/oas/default.aspx?gprid=6527&st=1&wfxredirect=1&sd=gnThis(free)tool from M$ looks like it has possibilities, although I've never run it myself and can't verify first hand how useful it is or for it's (apparent) ease of use:
Microsoft Baseline Security Analyzer http://www.microsoft.com/downloads/details.aspx?FamilyID=b1e76bbe-71df-41e8-8b52-c871d012ba78&displaylang=enBrief DescriptionThe Microsoft Baseline Security Analyzer provides a streamlined method to identify missing security updates and common security misconfigurations. MBSA 2.1.1 is a minor upgrade to add support for Windows 7 and Windows Server 2008 R2.
OverviewTo easily assess the security state of Windows machines, Microsoft offers the free Microsoft Baseline Security Analyzer (MBSA) scan tool. MBSA includes a graphical and command line interface that can perform local or remote scans of Microsoft Windows systems.
http://technet.microsoft.com/en-gb/security/cc184923.aspxMicrosoft Baseline Security Analyzer (MBSA) is an easy-to-use tool that helps small- and medium-sized businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance. Improve your security management process by using MBSA to detect common security misconfigurations and missing security updates on your computer systems.
MBSA 2.1 Frequently Asked Questions
http://technet.microsoft.com/en-us/security/cc184922.aspxThere's some screenshots of the tool's GUI on this DSL forum:
http://www.dslreports.com/forum/r23231898-Microsoft-Baseline-Security-Analyzer-211