Welcome to the Microsoft Q&A Platform. Thank you for reaching out & I hope you are doing well.
I understand that you would like to block internet access on an Azure VM except for Microsoft services.
You can leverage Azure Firewall service tags
- You can find a list of all available service tags along with whether or not supported by Firewall here
- For Office 365, see : Use Azure Firewall to protect Office 365
For e.g., you can use "AzurePlatformLKM" tag for Windows licensing or key management service.
Thanks,
Kapil
Please Accept an answer if correct.
Original posters help the community find answers faster by identifying the correct answer.