When you put a group in the Not Access Server field in your server document, the group doesn't have to be a "Deny List Only" group. A regular multi-purpose group will work. However, if you do make the group type "Deny List Only," AdminP is supposed to leave it alone. Here is a technote.
http://www-1.ibm.com/support/docview.wss?rs=463&context=SSKTMJ&q=deny+group&uid=swg21101149&loc=en_US&cs=utf-8&lang=en+en