Hi,
You can try enabling the group policy Computer Configuration > Administrative Templates > System > Device Installation > Device Installation Restrictions > Allow installation of devices that match any of these device IDs and add the desired Hardware IDs
To restrict user access to only the required application. you can use AppLocker rules. Open secpol.msc
navigate to Application Control Policies > AppLocker and create a new executable rule.
Best Regards,
Ian Xue
If the Answer is helpful, please click "Accept Answer" and upvote it.