Here is my dilema, I need to create several gpo's for wsus and I want to use security groups to assign the policies to computers. would it not be much easier to do it this way than it would to move them around from ou to ou, especially since I am not a domain admin. I can see that my server admin guys have servers in domain local groups for wsus and they seem to be working properly but what amazes me is that the groups are not in the ous that have the policies tied and there is no ref in the policies about the groups. Why is it that we cannot use groups OTHER THAN authenticated users and domain computers for GPO??? I can add a group to the policy but NOTHING happens to the systems in that group. This does not seem logical.