In the Delegation tab of a GP in the Group Policy Management console you can restrict certain user accounts from receiving a GP by setting their account with a DENY Read permission. However doing the same with a computer account doesn't work to prevent that account from receiving the GPO.
Is there a way to block certain computer accounts in any regard other than setting up blocking inheritance with OUs? WMI perhaps? I'd prefer not to do the method of separate OUs and blocked inheritance, that would be a bit messy.