paxx, I've tried to do what you are attempting to do with no success. After searching on Symantec's support site, I came to the conclusion that there was not a way to do. At least, no relatively easy way, although it may be possible with some advanced rights configuration or group policy editing.
On your second question, yes. It does take some user rights changes. You could create a special group, put those users in that group, remove them from the normal users group, and set appropriate rights to the program directories that group could and couldn't access.
Alternately, you could install the restricted programs to an alternate path (not Program Files) and restrict rights to that path.