First, you can restrict users from installing software on one computer, by changing the permissions for the HKEY_LOCAL_MACHINE\SOFTWARE, HKEY_CURRENT_USER\SOFTWARE and HKEY_USERS\.DEFAULT\SOFTWARE registry keys. Run regedt32, and remove their Set Value and Create Subkey permissions in SOFTWARE. Change the Everyone group's permissions from Special Access to Read. Then, users in the group will have only Query Value, Enumerate Subkeys, Notify, and Read Control permissions. Second, you can implement a local software restriction policy using Group Policy to block specific executables or msi files from being run on the target user machine. You don't need a Domain for this. Third, you can block users from accessing the websites where they can download such software by configuring your firewall/proxy server (if those aren't available, you can use a HOST file).