@HASSAN BIN NASIR DAR ,
As per the description, I can scope that you want to restrict users to installing unwanted software on the endpoint and only install managed applications. Please refer to the following article to create and perform the application control policy - https://learn.microsoft.com/en-us/mem/configmgr/protect/deploy-use/use-device-guard-with-configuration-manager
(If the reply was helpful please don't forget to upvote and/or accept as the answer, thank you)