Restricted Groups applying to specific global groups

I'm missing something simple and it is driving me crazy.
I have an OU that needs to have the managers all have local administrator access. Simple, I says. Create a GPO that adds the global group to the computers local administrators group, link it to the OU and then set security filtering to only apply for the managers security group. Nope. Tried creating a global group that contained all accounts that aren't in the managers group and denying them apply group policy in the Delegation tab for the group policy and nothing.
What am I missing? Can this not be done?
I have an OU that needs to have the managers all have local administrator access. Simple, I says. Create a GPO that adds the global group to the computers local administrators group, link it to the OU and then set security filtering to only apply for the managers security group. Nope. Tried creating a global group that contained all accounts that aren't in the managers group and denying them apply group policy in the Delegation tab for the group policy and nothing.
What am I missing? Can this not be done?
Comments
Create a new security group and add the users you want then apply permissions for that group.
2020: GCIP | GCIA
2021: GRID | GDSA | Pentest+
2022: GMON | GDAT
2023: GREM | GCWN | GSE
WGU BS IT-NA | SANS Grad Cert: PT&EH | SANS Grad Cert: ICS Security | SANS Grad Cert: Cyber Defense Ops
I wish I was the one making this complicated because then it wouldn't be complicated.
Thanks for the reply and sorry for the late response but things are absolutely crazy at work.
To achieve what you have in mind, create a GPO (or use an existing GPO), configure the DOMAIN\Managers security group to be a Member Of of "Administrators" in the Restricted Groups node, then scope the GPO to the OU that contains your domain computers. The result will be that the Managers group is added to the local administrators group on top of existing memberships, such as .\administrator and Domain Admins.
Edit: I wouldn't recommend making anyone local administrator, especially not managers
Casual reading: CCNP, Windows Sysinternals Administrator's Reference, Network Warrior
I second that. Also what you said about actually achieving a solution. But mostly, the bit about restricting local administrator access tightly.
The situation has been worked out. I don't know why this was such an issue and made to be more complicated than it needed to be in the first place but that is what happens sometimes.
Onward and upward (I guess)
This x 100.
work-life balance