The thing of it is this, the SEMS/PGPUN has no function to push out client updates whatsoever. It cannot remotely upgrade your clients for you. All it can do, is let the users know a newer version is available. After which it is up to the users to download and upgrade the client themselves (which users usually can't do as they are not local admins).
This means (as Mike Ankeny says, Thumbs Up!) you'll need to look into pushing the upgrade via some software management tool (Altiris/SCCM/LanDesk/whatever) instead. Going via another tool also means there's no point in messing with the groups in the SEMS, so you can save a bit of time here at least!
As far as pushing upgrades via the SEMS in the future, I'd suggest subscribing to the below article:
http://www.symantec.com/docs/TECH204448