Sure you can block inheritance of the GP to the service accounts. This will leave you open to things like brute force or dictionary accounts. We apply our password policy to everyone regardless of what they do. However, we do not allow the service account passwords to expire. This way it is the same thing everytime the service people use it and also locks the account out if someone tries a Brute force attack.