Firewall rule toblock the internet access exept

Hello, I need to set up a firewall rule to block the internet access, except (O365 (for email ..etc), Windows update, some ip addresses and port to connect our server etc..).
We cannot use :
• Static DNS
• Web Proxy
• Content Filter
• Layer 7 Firewall

Do you have any idea how to set this up?

The server parts (ports IPs) are probably easy, the Windows update part… not sure.
You may be better putting a windows type server on the LAN network and all PCs get their windows updates from that???