Hello,
I want to prevent a couple or users and computers held in a specific OU, to be not able to install any .exe files. What is the best practice/tools/GPO to achieve this? I wish if I can stick to a GPO!
Please note these users are and need local admin privilege for their work culture but I don't want them to install any single piece of an app and when they need, I will strike the 'RUN AS' and pump my domain admin credentials.
I don't think disabling Windows Installer (GPO) is not a good idea, is it? Because it stops me too...
Tips are thanked :)