@MarcAF Thanks for posting in our Q&A.
For this issue, based on my check in outbound rules on windows server, there is no place to add FQDNs.
Based on my research, the IP address for the Windows Update web site constantly changes and it is not a fixed address. Also, there is no official publication of the IP addresses. We still can't add IP address. So, there is no method to make it via Intune.
Given this situation, did you consider deploying WSUS server to make it? We can point windows update to WSUS server, then we can connect to WSUS server to get windows update instead of connecting to Microsoft Updates Server.
Hope it will give you some ideas.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.