Appears to be by design there is no way to exempt a user or group unless they are in a different OU so you can apply a different policy group. You also need to be careful with sub OU's even though you can enable inheritance blocking items applied at the…