Like I said, put nothing in the policy path.

This can be part of your logon script. The UDF should be part of your script or called from your script. I posted a fully working solution with the If ingroup(...) stuff.
_________________________
Mart

- Chuck Norris once sold ebay to ebay on ebay.