Thanks,
I'm using Windows Server 2012 R2 functional level + W7 clients
I'm gonna try this way as well, so far on my side it finally started showing up in the results (I guess it needed more time (couple of hours))
but another issue that came up is that i noticed from the list of the computers i've put this policy on, some got the policy as "applied" and some have it as "denied" which makes no sense because all users/computers from that list are have the same other policies (technically) but somehow it's getting denied for some reason.
what do you guys use to narrow down where these permissions are getting inherited from? (something more detailed than GPresults)
Thank you.