Hello Alfredo,
You could create an allow user-based FW rule/Web Filter Rule with similar settings to the KBA below for your email domains and MS updates on top of your "Block all" FW/Web Filter Rule/ App control rule
Email: https://support.sophos.com/support/s/article/KBA-000004733?language=en_US
Win updates: https://support.sophos.com/support/s/article/KBA-000004980?language=en_US
Also, please note that when configuring a "Block all sites" except email/s and Windows update, you should not include CDNs on your blocklist and other necessary resources to fully load/access your allowed websites and resources.
Raphael Alganes
Global Community Engineer, Support & Services
Are you a Sophos Partner? | Product Documentation | @SophosSupport | Sign up for SMS Alerts
If a post solves your question, please use the 'Verify Answer' button.
The award-winning home for Sophos Support videos! - Visit Sophos Techvids
Hello Rafael, thank you very much
I will proceed according to your instructions
Cheers