Since a Network Group may contain network objects that are not allowed in this place, and that would simply not work, we decided to go the simple route. We're thinking about a way of making this more transparent to the user by either only allowing a group containing "allowed" objects, or by showing more descriptive error messages.