I don't see any mention here, but as someone who deals with front-line response to users regularly, take a look at CryptoPrevent from FoolishIT (yes, really, https://www.foolishit.com/vb6-projects/cryptoprevent/) and HitmanPro.Alert (http://www.surfright.nl/en/alert) with CryptoGuard. The first does a bunch of local policy setup to restrict where executables can run along with some optional subscription signature watching;the second does more watching for encrypting behavior including on a host sharing files via SMB.
I also recommend making sure that shadow copies are turned on and allocated plenty of space - including on a separate partition or drive if the user in question regularly comes close to filling the drive. It's not a backup, but it is much faster to restore from a shadow copy than from an offsite backup.
edit: added links