I thought I was blockikng those ports, and users cannot map to the c$ share, but they still can access it via the Start-run or IE explorer.
Might not be able to help you. I started using CSA at version 5.1 and am now running 6.0.
With those versions, I would just create a Network Access Control rule to Priority Deny any application from acting as a server for $Microsoft-DS on any network interface. This would stop anything from connecting to any share on the computer.