Denying a GPO using this method should only be a last resort. There are multiple other ways to have the GPO only apply to certain objects (link only to certain OUs, security filtering, item-level targeting, etc).
Yes Rich hence I have mentioned the security filtering in this link