I seems that SEC 5.2.2 has a known bug (Sophos seemed aware) but no KB for it yet!!!!
One way to work round it is to disable AD sync on your subgroups and manually move the computer from Unassigned to the correct group. you can then protect those computers.
Anyone else have this problem and resolved it?
This thread was automatically locked due to age.