Hi,
You can add a Route table with a rule where you can use service tags which states, if the destination is <Service tag> next hop internet.
By doing this, you can route the traffic from Azure VNET to Internet for the service tag IPs, and rest of the traffic will go to On-Prem.
Note: Not all the services are available in Service Tags in UDR. I don't see Intune in here yet.
Regards,
Karthik Srinivas