I believe the pieces in Windows are already in place to do this, you can restrict an application to only be able to write in a preset set of directories, etc. What they need is an set of standards for applications that makes this possible, and then for application installations to use that by default.