Add this to the user's registry (On the local machine, not at the server.)
Depending on your version of Outlook, the 10.0 might by 9.0, etc.
hcu\software\microsoft\office\10.0\outlook\security
Key: Level1Remove
String Value: .exe
I forget what seperates string values so you can add more values; either , or ;
There is an admin security piece that can be put on the server to handle this stuff, but we only have one or two users with Outlook XP so far and I don't feel like playing with that stuff on the server yet!