Blocking an Install of an application, but allowing the use of the application in Sophos Central

We are working on using group policy to push Google Chrome to users using our own configuration, and want to prevent the ability for users to download chrome on their own. I am assuming this is some mix of web control/application control in central policies but am coming up short finding a clear answer. Is there a way that we can stop our users from being able to install, but still allow the application to run on a machine? (Including the installer via GPO)? This is a Windows 10 environment running Sophos Central Intercept X on all endpoints.

Parents Reply Children
No Data