You are going to need to purchase a third party product that performs WhiteListing. Microsoft does ok on 2012, but I would recommend a third party product, the name slips me but there is a product out there that works from a centralized point of view
to control a group of devices from a central locations.
Check out Bit9, IIRC they are the vendor I was thinking of.
https://www.bit9.com/
--
Paul Bergson
MVP - Directory Services
MCITP: Enterprise Administrator
MCTS, MCT, MCSE, MCSA, Security+, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
http://www.pbbergs.com Twitter @pbbergs
http://blogs.dirteam.com/blogs/paulbergson
Please no e-mails, any questions should be posted in the NewsGroup. This posting is provided "AS IS" with no warranties, and confers no rights.