Any way to block all DNS queries and whitelist some?

For MS, you might be able to use this RPZ. I know nothing about the list so make sure you review before using!

https://raw.githubusercontent.com/hagezi/dns-blocklists/main/rpz/native.winoffice.txt