My first recommendation would be Defender for Cloud apps and a CA Policy if you are licensed:
https://learn.microsoft.com/en-us/defender-cloud-apps/use-case-proxy-block-session-aad
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
How to stop/prevent users to upload and download from Teams, OneDrive for business and SharePoint Online for users which includes .EXE, .MSI and any other executable files?
Is there any policy via Intune or Azure AD side that we should create and apply across org or group of users?
My first recommendation would be Defender for Cloud apps and a CA Policy if you are licensed:
https://learn.microsoft.com/en-us/defender-cloud-apps/use-case-proxy-block-session-aad
As @Andy David - MVP suggested you can use Microsoft Defender for Cloud Apps (MDCA) to block uploads and downloads to Onedrive or Sharepoint Online in realtime only for browser sessions!
Uploading or downloading through for example Teams or copying One Drive synced files in file explorer are not covered by the conditional access proxy policies.
You can also create file policies to for example change permissions of files with a .exe extentions. https://learn.microsoft.com/en-us/defender-cloud-apps/data-protection-policies
Form SharePoint, there is no OOTB functionality to restrict specific file extensions when uploading files.
From OneDrive, go to SharePoint admin center -> Settings -> Sync -> Block uploads by file type.
https://learn.microsoft.com/en-US/sharepoint/block-file-types?WT.mc_id=365AdminCSH_spo
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.