@Bob Frick , For our situation, I have two suggestions for the reference:
Suggestion 1:
Create a new security group without the specific user. Change the office 365 app assignment to this new group.
Suggestion 2:
Create a filter to target the device. To create a filter, here is a link for the reference:
https://learn.microsoft.com/en-us/mem/intune/fundamentals/filters
Under Microsoft 365 app assignment, choose "Exclude filtered devices in assignment" to avoid the app installation.
Hope it can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.