The firewall has it's L3/L4 rules and it's L7 content filters.
Group policies can also contain these rules but can dynamically pushed to a network client.
However group policies can also apply to a wireless client and then it's the AP firewall that counts.
These rules in group policies can override the firewall or in case of content filtering it can work additive to the existing policies.