You can enable STP Protection on a per-port basis.
To prevent an end station from initiating or participating in STP topology changes, enter the following command at the Interface level of the CLI.
device#(config) interface ethernet 2device#(config-if-e1000-2)#stp-protect
This command causes the port to drop STP BPDUs sent from the device on the other end of the link.
Enter the no form of the command to disable STP protection on the port.