In a workgroup setting, each machine is handled separately, just
as if it were in a workgroup of size one.
Local policy applies to all accounts equally, but there are a few
options for getting around this.
One is http://support.microsoft.com/?id=293655
Another is to set a deny for admins on the system32\GoupPolicy dir
One may also simply use direct reg editing
And the last is to get third-party tools