That is what Windows Defender Application Control does. It's probably the most cutting edge solution on the market actually.
It's a pure whitelisting solution where every single executable and kernel driver needs to have an approved digital signature or matching hash value or they won't be permitted to run.
It's virtualization assisted and can't be disabled without rebooting and if you use a digitally signed policy and someone tries to remove it, the machine will refuse to boot.
The coolest thing is, it even expands to the scripting languages built-in to Windows so PowerShell execution is restricted according to policy etc.
In practice of course, it's a big pain in the ass to manage - many software are not digitally signed etc.
Every single artifact of every program needs to be digitally signed or have a matching hash in the policy or they won't be permitted to run.
For example, suppose a software installer: the .msi itself is digitally signed so can easily be permitted to run... But then, during installation it unpacks an .exe into %temp% that isn't digitally signed and attempts to run that - oops, won't run. I've come across even Microsoft software that does this.
https://docs.microsoft.com/en-us/windows/security/threat-pro...