@J-3804, Thanks for posting in Q&A.
From your description, I know you want to set up BYOD for Windows in Intune while protecting organization data.
If you want to block users copying data from the resource, we can create a Windows Information Protection policy, When the apps are added in the protected apps list, the data in these apps are corporate data, WIP will encrypt the data on the device.
https://learn.microsoft.com/en-us/mem/intune/apps/windows-information-protection-policy-create
But if you want to block users accessing the resource, we can create a Conditional Access policy.
https://learn.microsoft.com/en-us/mem/intune/protect/conditional-access
https://learn.microsoft.com/en-us/mem/intune/protect/create-conditional-access-intune
Hope above information can help you.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.