Get it working? If not, PM me and I'll come back to this. The basic premise is that you have two parts of a GPO, machine and user, and these parts will apply to the corresponding objects in your OU (you can apply GPO/security policy settings to Local, Site, Domain, or OU only but you can use security settings and WMI filters to limit this even further). If you have a "Users" OU that has only user objects in it, then only the user portion of the GPO will be used (such as IE restrictions or folder redirection). If you have a "Computers" OU with only computer objects in it then only the computer portion will be applied (such as assigning software installation or most of the core security settings).