I have to create some restrictions for general users in a W2K-Domain. I made a new OU only as container for this GP. Then I made a new group for the needed users and put them in. Then I made a new OU and moved the group in. Then I linked the GP to this OU – but nothing happened. Only if I place the link to the DomainObject the policies working – but also for the Admin too. What could be the problem ? Has anyone an exactly desciption to come to success ? Many thanks.