I required to block some windows group from accessing to the internet but only allow to microsoft update.
I can see on the application with name 'Windows Update' and in the Network Policy i can't select this application.
On my mind is i must create an application rule to allowing desired windows group to this application, but what should we do for this group on network policy?
Only using this application rule, the server is not able to connect to the windows update.
If i make network rule for this group with destination set to 'Any' all host under this group is able to access to the internet.