Hi @TechQ
I'm pretty certain that you would need to only assign All users and add that user to the exclude list.
If you add All devices this will conflict with the policy as it then becomes a device based condition.
----------------------------------
If this is helpful please accept answer.