Hi Arren Bul-an,
The only way this is possible today is to imploement Un sanctioning via policies and to add scoping exclusion for individual apps. - https://learn.microsoft.com/en-us/defender-cloud-apps/mde-govern#block-apps-for-specific-device-groups
*If you find the answer above helpful, please "*Accept the answer" to help anyone in the community who might have a similar question to quickly find the solution.