EDIT: I misread your question. My initial reply was about a domain.
For a user
Configure suhosin so that exec permissions CANNOT be overriden
Edit his php-fpmXX.conf files
Add the full list of functions to blacklist
As long as users can't customise their httpd.conf, you're safe
For a domain...