In the main Web Console window select Devices → Policies and policy profiles.
Select the policy you want to configure.
In the <Policy name> window that opens, select the Application settings tab.
Select the Execution prevention section.
You can do the following actions in the Prevention rules group of settings:
Add an Execution prevention rule to the list.
Change Execution prevention rule settings.
Remove an Execution prevention rule from the list.
If you configure the policy settings, in the upper right corner of the group of settings, change the switch from Undefined to Forced.
Click OK.
In the policy properties window, click Save.
Execution prevention rules do not apply to files located on compact-disks or in ISO-images. Execution or opening of such files is not prevented by the application.