Originally Posted by
dan400007
A quick way around this is to create a new GPO with the Logon as Batch Job settings, link the GPO to the appropriate OU in your domain and then edit the security permissions on the GPO and remove the "Apply Group Policy" permission for "Authenticated Users", this can be done in the Group Policy Management Console, select the GPO, click the Delegation tab and click advanced. Then add the computer account to the GPO Security settings and give it Read and Apply Group Policy permissions.
The GPO will then be within the scope of the computers in the OU, but only the computer(s) you specify in the permissions will apply the GPO.