Ok, I've tested the compatws.inf security template but
unfortunately it's not what i'm looking for. After
applying it, users on the test machine are able to run
legacy apps but are also able to install apps. Where as
before applying the template they could NOT run legacy

At this point I dont think any template has what i'm
lookin for. So, my question is this:

Does anyone know which specific policy I can edit so that
the Power Users group is NOT able to install anything but
can run legacy apps?

Any help is GREATLY appreciated. Thanks in advance.

