I'm glad that you were able to resolve your issue and thank you for posting your solution so that others experiencing the same thing can easily reference this! Since the Microsoft Q&A community has a policy that "The question author cannot accept their own answer. They can only accept answers by others", I'll repost your solution in case you'd like to "Accept" the answer.
Issue:
You wanted to block all connections to https://compliance.microsoft.com, except through a jumpbox which is recording the session.
Resolution:
You used Microsoft Defender for Cloud Apps to identify the source public IP. Then you created an access policy that allows access to that IP and blocks access from all other sources.
If you have any other questions or are run into issues customizing the access policy, please let me know.
Thank you again for your time and patience throughout this issue. We appreciate you sharing your solution and screenshots with the community.
-
If the answer accurately describes the issue and resolution, please consider Accepting the answer. This will help others in the community who might be researching similar information.