Hi,
When a user is added to the Protected Users group a number of additional security constraints/restrictions are applied to the account, which can break existing functionality, especially if the account is used as a service accounts. One of the main restrictions is that is applied is that NTLM authentication can't be used, if your applications are using NTLM then they will be inaccessible.
Have a look at the article below which contains the details of the additional restrictions that are applied. You will need to check if your applications will be impacted by these restrictions.
Gary.