try creating an ou. placing desired users and computer objects in that ou, then apply the GPO to the OU that they are all in. Should work fine.
try to just use "groups" for resource access, ie: file shares, printer access, etc...
watch what you apply at the domain level, if you apply...