@Danissimode, Thanks for posting in Q&A. Based on my researching, I find Intune's endpoint security App Control for Business policies manage which apps on your managed Windows devices are allowed to run. Any apps that aren't explicitly allowed to run by a policy are blocked from running.
For your scenario, it seems you want to just block one app. You can consider AppLocker to block one app.
From the picture you provided, I find the firefox.exe under Tor Browser can't get the publisher information. You can download the firefox.exe file from their official article to see if it has publisher information. If still not, you can contact their support to see if they can add the publisher information in the app.
Then you can consider using File hash :instead to see if it can block the app.
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.