Hi there, sorry to open an old topic, but Im having a similar problem..
In this case, I wanna prevent users to run .bat files (they create these with notepad)..
We have a mixed pc environment (XP/2K) and server 2k3 .. so using the software restriction policies from the AD only work for XP but not for the 2k pcs..
I already 'disabled the command prompt', also enable the 'dont run specified win apps'.. but since it's a .bat file.. they still have access to the command prompt..
I could use the reg editor, but since we have so many in different buildings.. I was wondering if there's a way to prevent bat files from being run from the user account (they're limited accounts)..

any help would be appreciated.