Assign No Access to Everyone on \%systemroot%\system32\ mprui.dll and to \%systemroot%\system32\net1.exe to restrict mapping of network drives. Users could still use commandline net use commands. If you set No Access on \%systemroot%\system32\net.exe the user can not execute the net command and any net uses in the profile will not work. You might experiment with setting the permission on net.exe after assigning required shares in the user profile.