Policies are applied to GPOs, not groups, but you can (as you say) put the
group inside the GPO and then you can edit the DACL for the GPO (security
tab in its properties iirc) and choose which groups get the apply group
policy right assigned to them and which do not. This should do it.