Hi,
As far as I know, you may have no way to achieve this goal in WORKGROUP environment.
To achieve this goal, an easy way is to create a DOMAIN environment, create two OUs for both Domain Admins and Non-Domain Admins. After that, you may
create a GPO to disable the Run box and link this GPO to the Non-Domain Admins OU only.
In addition, you may also use Security Filtering to refine which users and computers will receive and apply the settings in a Group Policy object (GPO).
For the detailed information, please refer to the following Microsoft TechNet article:
Security filtering using GPMC
http://technet.microsoft.com/en-us/library/cc781988(v=WS.10).aspx
Regards,
Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.