You can configure options in Web Content Zones in Internet Explorer to not allow
downloads. This can be configured via Group Policy and of course users will also need
to be restricted from changing settings. This will not stop them from downloading
files via other browsers/programs if they are able to install them on their computers
and have necessary network access. A firewall to manage outbound access to only
allowed ports would also be a great help in restricting downloads by keeping users
from using ftp, file swapping programs, etc on the ports that they use. --- Steve
Web Content Zones can be configured on user/group basis for a domain, it is part of
Group Policy user configuration. Hardware firewall rules work by machine ip address.
You can control user access to the interet by using a proxy/firewall server like
A. --- Steve