This is my first AD build from the ground up on an existing system that has not been a migration or an upgrade. The problem is that I have an OU such as IS and in that OU I have secuirty groups and users from the IS department. Now for example I apply the GPO to the IS OU lets say to disable the control panel. I enable Enforce on the GPO and I login underneath an IS user account on a windows XP PC. Now once logged in I run the GPUDATE /force and then the GPRESULT and I can see that the GPO was applied so I login/logout and still can access the control panel. I then reboot the PC and still can access the control panel. I then download the GPMC and use that instead to run the wizard against the account I am using and it says that the GOP is being applies but again I can still access the control panel. Am I forgetting something here?