Hello, please. I searched a lot about this matter and asked a lot, but no one answered me, and there were some people who answered me, and unfortunately their answers were wrong.
I want an island solution to prevent the standard user from installing programs
Of course, a standard user cannot install programs that need administrator permissions, but there are very, very many programs that do not need administrator permissions and are installed in the AppData folder.
What I did is
I have activated a feature in the settings for the admin user called installing programs from the Microsoft Store only, but unfortunately the standard user can install programs from a flash drive or by transferring the exe file from his phone, and also when he downloads the program file from the browser, he can open it by clicking on Right click on the file, then properties, then remove the block and it installs the browser or program with ease. Examples of these programs include most browsers that do not need administrator permissions, as well as programs such as Telegram, Zoom, and other programs.
I tried all the solutions on the sites, but to no avail
Knowing that these programs are installed in the AppData folder, some programs can be changed where they are installed, such as Telegram
What should I do 😪