
Explanation/Reference:
Restricted groups allow an administrator to define the following two properties for security-sensitive (restricted) groups:
Members
Member Of
The "Members" list defines who should and should not belong to the restricted group. The "Member Of" list specifies which other groups the restricted group should belong to.
Using the "Members" Restricted Group Portion of Policy
When a Restricted Group policy is enforced, any current member of a restricted group that is not on the
"Members" list is removed with the exception of administrator in the Administrators group. Any user on the
"Members" list which is not currently a member of the restricted group is added.
Using the "Member Of" Restricted Group Portion of Policy
Only inclusion is enforced in this portion of a Restricted Group policy. The Restricted Group is not removed from other groups. It makes sure that the restricted group is a member of groups that are listed in the Member Of dialog box.
http://support.microsoft.com/kb/279301
hints: if user was not added into local restricted group, it will remove from administrator group, even it already was added to administrator group.
