Hello
Greetings!
I mean you remove all the lists within "allows Windows to run the Specified Programs only".
Then you can configure the lists within "Do not run specific Windows applications" policy, you can add the lists what you do not want to run by the domain users.
Please test it in lab first if needed.
Best Regards,
Daisy Zhou