I would suggest using the security policy editor in windows to limit the use of regedit and cmd. Here is a LINK to a page on the technet that give an explanation on how to do this.