I must have been doing something wrong cause when as an admin with Full Control, I add a group with the right permissions to the GPO and that group has not been 'delegated' through the 'Domain Delegation' tab, the permissions work fine and the user account can read and edit the GPO....