Hello, HJLBX.
If a program option "Can be started" is set to "Allow in isolated environment", this program will be run in isolated environment.
BUT if its parent program option "Can start programs" is set to "Allow", child program checking isn't made, it is allowed. So use this option with care, and "forced" programs concept is included by design.
Also you can use Isolation mode when all unknown programs are blocked without notificatons.