I understand that you want to permit the outbound access to CDN by using FQDN. NSG can't fulfill your request because you can use only IP address in NSG.
In this scenario, you need to use Azure Firewall or Network Virtual Appliance. These equipments support to use FQDN in its security rule.
Best regards.