security permissions are still flawed
administrator group still gets over rided by the users group, so if your a administrator you will still need to use single usernames on folders instead of just using the administrator group
so if you have
administrators = full control
users = read only
your account will still need to run everything with elevated administrator rights in the group policy, while if you just add your single user name, you won't need elevated administrator rights