Yeah, the Endpoint Verification extension is necessary.
Other than that, the rules look OK, with the caveat that @Scott mentions. 🙂
This is what I have to block old versions of macOS. Sorry about the popor image quality. It wasn't possible to print the entire page to PDF, so I had to take a zoomed out screenshot, and then zoom in again in Paint. 🙂

Oh, I also found this interface, which isn't supposed to be available for Education. I still set them all to Warn. 🙂
https://admin.google.com/ac/context-aware/security-advisor
--
https://wheretofind.me/@NoSubstitute