Try putting both groups under policy #1 so you will have 1, 1.1 (enabled
users), 1.2 (restricted users). At the moment all users will be hitting
policy 1.1, those in the group will be allowed and those not will hit
the implicit deny and not even get ...