Press the key combination Win+R. a dialog box Appears "Run", in which enter gpedit.msc and press Enter. This opens the local group policy editor.
In the left part of the window navigate to the directory "computer Configuration" > "Windows settings" > "security Settings" > "Policies of restricted usage of programs". If the policy has not been assigned yet, click the menu "Action > Create policy restricted use programs". In the right part of the window click the right mouse button on the newly created parameter "Designated file types" and select "Properties". Scroll down to the "Designated file types" to determine the presence of MSI and EXE formats. If any of them is missing, add it using the input field "Extension" and "Add" button at the bottom of this window. To put changes into effect, click "Apply" and then OK or just click OK if no changes were made.
In the left part of the window, select "security Levels", and in the right pane right-click on the parameter "Forbidden" and in the appeared menu, click "default". In the new window click the "Yes" button. The system will now prevent users from running all applications (including. EXE installers and. MSI) in the list of "Designated file types". The following instructions describe the steps to block access to the local group policy editor.
Activate the guest account. To do this, click "start" > "control Panel". Further two variants are possible: if the control panel appears, select "user Accounts" > "Manage another account", as if the categories, find the "user Accounts and family safety" and click it to "Add or remove user accounts". A new window will appear where you can click the button "Guest" and "Enable". You have activated the account under which the user will log in to the system.
Select the administrator profile, i.e. the account under which you log in. Click on "create a password". In the window that appears, enter the password, confirm it, and optionally write a prompt. Finally click on "Create a password". Thus, you have allowed unauthorized users access to the system only through the user account "Guest". Through it they will not be able to open the local group policy editor, and, thus, remove the block to install programs.