This may or may not work and you don’t say in the original question. Are the local users allowed to make changes to the system? If they are not allowed to make any changes to the system, then when the system logs in then the changes are not allowed. In the login script that you are running in Group Policy you may have make a change telling the system that this change is allowed, then put the change in. We had a login script running on the domain controller doing something similar in that we had to turn off Automatic Updates. As long as the end user machine does not have rights to make changes, the changes will not be made.