Hi,
Based on my research, we don't need to do this for all he local accounts.
We did this to protect the local administrator account.
Or if you do need to do this, you can add the local accounts into a group.
Then you can use the GPO to deny the rights to the local group.
Best Regards,