Guys, how do I prevent users from running executabels from usb sticks? I do want them to save and read files from the usb sticks, but not any executable files such as bat, exe, vbs etc.
You could make their user accounts to be a standard user instead of administrators, then they will not be able to run anything that will affect the system or other users. However, this will affect them being able to do this at all, and not just from USB sticks.
You can use Software Restriction Policies to only allow users to access programs that are in the Program Files, or Program Files (x86) for instance. It's a bit beyond me, but I'm sure Brink or another can get into more detail. I found this pod cast: