Mobile profile and GPO and security group interaction

I have set up mobile profiles (the client insists) according to this document: and it works, but there is something I do not understand.
Step 2: creation of a security group. It seems that a mobile profile should be created for any user who places in this group, regardless of the machine they access, but it doesn't work that way for me. In my environment, mobile profiles only apply if the user and the computer are added to the security group.

Is there a problem with my configuration or is this behavior expected? If you wait, why am I missing? It seems to me that the policy should apply to any object that is in that group, be it a user or a computer.

Thanks in advance.