Remove the Domain Users from the local Users group, and add only thier account. This is done locally, not through AD or GPs.