28,655 questions
Hi,
You can use Applocker (via GPO) , to allow only allowed user or groups to launch %windir%\system32\cmd.exe.
In your case,you should sepcify the path of CMD.exe %windir%\system32\cmd.exe and specify on local asministrators group .
Please don't forget to mark helpful answer as accepted*****