Depends on the required group settings. Simplest approach is to only let members post - so just change the group settings.
If you need some non members to post, then use a compliance rule. Block posting to the group at the root level of the org and disable the rule at the OU level of the people who you do want to post. So do an advanced content match for recipient header equals the name of the group for internal sending.