I'm with dput, we did the same. Work on the premise that the user can probably gain access to an alternative browser that has not been locked down, rejecting anything not coming from the proxy server at the firewall is the best way of dealing with it.
Carlsberg don't run I.T departments, but if they did they'd probably be more fun.