I have created a new group policy on my Win2K3 DC so that I have a separate Windows Update policy for servers and workstations. I have restricted the server GP to only members of the Domain Servers security group. I have confirmed that all servers are members of this group in AD. However, I have one server that is not picking up the new policy. When I run Group Policy Results, the new Windows Update policy is shown as Denied, with the reason as 'Inaccessible'. When I look at the Security Group Membership when Group Policy Applied, the Domain Servers group is not listed. The problem server is a Win2K3 VM running under Virtual Server 2005. However, I have other VM's running both under VS and Hyper-V that don't have this problem. Any help is appreciated.