Hello,
Thanks for posting your question in the Microsoft Q&A forum.
Actually, there are several approaches you can take, I think one can help you is using "Group Policy" , with Utilize Group Policy Objects you can enforce restrictions that are not joined to your AD domain.
configure GPODs for blocking access to application or services based on the device's domain membership status.
I hope it can be helpful,
Best
Please don't forget to close up the thread here by upvoting and accept it as an answer if it is helpful
Zahra