Hi,
When you add the group into the scope on the GPO, did you give them the read and apply group policy permission under the delegation?
At the same time users in the group are also in the USERS OU, right?
Also, computers which the user account logon should be also added and have the read permission.
We should also confirm if there are any other GPOs which deployed the same setting.
You can run command: gpresult /h userreport.html to check all the settings for the users.