Active Directory organizational unit administrators can create, edit, and assign Group Policy Objects.
OU administrators can manage group policy objects from a machine joined to the domain using Microsoft's Group Policy Management Console, which is included as part of the Microsoft Remote Server Administration Tools packages. Active Directory - Remote Administration Tools. Please note that Remote Desktop connections to the Campus AD domain controllers are not permitted.
Resources on creating and managing group policy can be found on Microsoft's Group Policy TechNet homepage.
Because the campus user accounts are a shared resource, a Group Policy Object cannot be applied to them directly. Instead, loopback processing should be used to apply a GPO to machines that a user is expected to access. The GPO can further be filtered for specific users, if needed.