The goal of this policy is to block Security & Privacy from all users except the local admin that we push to all computers.
Here is what I have tried
Configuration profile
Under General
category = none
Distribution Method = Install automatically
Level = User Level
Under Restrictions
Preferences = uncheck extensions and security & privacy
Under Scope
Target = add the computers we want to push the policy to
Exclusions = "local account name" LDAP/Local User
Doing this leaves the Configuration Profile status as pending.
If I switch from user level to computer level it blocks security and privacy for everyone (the exclusion does not work).
