I know the best way to go for this would be whitelisting, since blacklisting is just unreliable in terms of bypass prevention.

But I’m unsure on how to implement it and if an actual complete bypass prevention is possible, even in extreme cases.

Pheraps a proxy and blocking all network access that doesn’t go to the proxy would be a viable option?

What is your experience with this kind of stuff?