Here's the answer for ISA 2000, other versions are probably similar.
Select the "Applies To" tab of your deny rule. Select "Users and groups specified below". For "Applies to" add the appropriate users, probably "DOMAIN\Domain Users".
Now add the accounts that should be allowed in the "Exceptions"
"The Key, The Whole Key, and Nothing But The Key, So Help Me Codd!"