When you create a GPO in active directory, it has to be applied to an OU to take effect.
Open AD Users and Computers, make sure you are viewing advanced settings
Go to the OU that is linked to the GPO and right click and select properties
You should see the following tabs: General, Managed By, Object, Security, and Group Policy. Select the Group Policy Tab.
If you haven't created a GPO, you will have to do it now
Select the Policy and then click on properties.
On the window that pops up, select Security.
You may have to add/remove groups to get it to work out right but, the basic idea is to have the deny box next to apply checked for the Admin group and the allow box next to apply checked for the TS Users
Hope that helps