Group Policy is applied only to the objects in the container that the Policy is applied to (this includes SUB OU's). The only valid objects are USERS and COMPUTERS. The two parts of the policy are applied to their counterparts... user policy only applies to user objects, computer policy only applies to computer objects. Computer policy is applied when the PC starts, and user policy is applied after the user supplies his/her credentials at login. Policies are applied in the order: local, site, domain, OU, Sub OU. Any settings that are specified in a policy will overwrite settings specified in a previous policy.
If you wish to generate a policy that only applies to a particular group, you should apply that policy to the container that holds all the computers or users that will be in that group (i.e. domain level). Then, with the advanced view, you adjust the permissions on the policy... you can specify which groups to "apply policy" (its a security permission), you can even deny "apply policy" to a particular group (i.e. admins) to prevent the policy from applying to them.
Hope this helps.
A+/MCP/MCSE/MCDBA