I am pretty sure that programs can be restricted more tightly than just using the app name in the Group Policy. I thought that there was a way of creating a Hash of the Application .exe such that the user cannot circumvent the Policy by changing the name. Has anyone tried this?