I think the "how secure is 802.1x" depends on how much 802.1x you're willing to implement, it's a bit of a broad standard from what I know.
You can require computer certificates, only available over an initial wired connection (if you're talking wireless) and a valid user cert once you've logged on before being dropped into the right valan etc all do-able with a 2k3 AD. Plus side of requiring both certs is you can revoke either

Yeah getting the initial comp cert could be a pain if you've got a huge amount of laptops to secure, but it only needs to be done once. I've seen it done with a couple of hundred machines in very little time.
This is all 802.1x for wireless connections, which seems fairly nails. - wired I've had no experience with.