I created a group policy object that is suppose to add a domain group to the local administrator group on all of the workstations in my domain. I configured the appropriate group as global group with security.Then I took group and added it to the restricted groups through right clicking on restricted groups. Then I added the administrators group to the member of property. The members property was left blank because I wanted to keep the existing groups already under the local administrator group. I log into the domain from the target computer using the user that belongs to my restricted group underneath the organizational unit with the group policy object. The problem is when I do a resultant set of policy I am getting back an error stating "The Policy engine did not attempt to configure setting" I try doing an gpupdate on the target machine and I am still getting the error message. When I apply the restricted group setting to the domain security policy console, the policy then works. It does not work when I apply it through the group policy console. I looked in the winlogin log file on the target machine and found nothing. Does anyone know whats causing this error message?