Instruction
1
To configure the restrictions you will need administrator privileges. Call command prompt by using combination of Win+R and type secpol.msc. Opens snap-in "Local security settings".
2
Expand the "Policy restriction". Under "object Type" double-click to expand the "Designated file types". In the properties window lists the types of files that are considered executable code.
3
4
Double-click to expand "Forced" and toggle the "Apply software restriction policies..." to "all except local administrators". Open the folder "security Levels" and double-click to expand "Unlimited". Click "set default" and OK to confirm.
5
Open the folder "security Levels" and double-click to expand "Unlimited". Click "set default" and OK to confirm.
6
Now other users can run only installed by you or by programs. By default, they are located in the folders Program Files and SystemRoot. If some programs are in other sections, you need to add them to the allowed list.
7
Expand the snap-in "Additional rules" and in the "Name" right-click on empty space. Click "Create path rule" and specify the path to the folder where you are allowed programs.
8
So users couldn't copy these folders prohibited software, configure permissions. Right click on the folder and choose "sharing and security". In the "Security" tab set permissions for each user group.