Hi,
I would suggest trying to do this after the default install. In GateKeeper go to the System Policies -third tab at the bottom in control panel- and add a new recipient, the Administrator, with default settings. Still in System policies add the AD group you are giving internet access to, again with default settings. Thirdly, again still in System policies, delete the default Everyone group. This will now give basic access to the AD group and the administrator only. From this point you can then refine and hone your WG service policies to suit your needs.
Before doing any of this however, save your WG registry settings. In GateKeeeper go to Options, Advanced click on Save Registry Settings and save somewhere. Also from Pascal,
Pascal wrote:However, to ensure that you cannot be bitten is to setup a specific access right policy for somebody that has administrative rights in the Remote Control Service. You can then set the System Policies to "Are Ignored" for that service and you will be safe while administering to the System Policies.
Let us know if this helps.