If I understand you correctly, you could create the two different
policies and use security filtering to ensure only certain policies
affect certain users.
Richard is correct. If you cannot (or don't want to) seperate those
users into different OUs, you need to use security filtering of the NTFS
rights: http://www.frickelsoft.net/blog/?p=28
But keep in mind that organizing objects in Organizational Units and
applying policies that way is much more clear to every admin in your org.