If IE is your browser then you need to create a software restriction policy blocking the executable from launching
Drill down: Computer Configuration -> Windows Settings -> Security Settings -> Software Restrictions -> Additional Rules
Create a new Hash or Path rule, With a Hash rule you will browse to the executable, for example C:\Program Files\Internet Explorer\iexplore.exe and set the security level to Disallowed. This will add the software hash as the rule so even if a user copies the exe and renames it the file will not run.
With the path rule, anything in the specified directory is off limits and cannot be run.
This works the same for any other browser or application. You will need to create an OU and add your workstations that you do not want to have internet access to that OU and link the policy there along with any other standard policies you have.
"I'm certifiable, not certified. It just means my answers are from experience...not a book