We are working on using group policy to push Google Chrome to users using our own configuration, and want to prevent the ability for users to download chrome on their own. I am assuming this is some mix of web control/application control in central policies but am coming up short finding a clear answer. Is there a way that we can stop our users from being able to install, but still allow the application to run on a machine? (Including the installer via GPO)? This is a Windows 10 environment running Sophos Central Intercept X on all endpoints.