from time to time there is no way to put a user based GP so it will install on their desktops but not on the server...
That's how you deploy the software to across the domain with exception to servers... why do you want to delegate the GPO to users instead of computers, whereas, your target is computers?
If you want to separate the server from the software update, you simply don't move the server to the OU container that the GPO applied. Logically, you only apply the policy to your users or groups if you want to included/exclude them. This case, your focal point is not user or group, but computers use OU is a proper way.
K