@Weghofer Thomas, Thanks for posting in Q&A. Based on my researching, I didn't find there's policy in Intune to block user to login to an office app when the app is downloaded directly from the app-store/play-store. In General, deploy Outlook to Android device in Intune is also via Google Play store. It is hard to separate.
As another option, we can block user to access Apple store to prevent the download. For Automated device enrollment (supervised), there's a setting named "Block App store:" which can block user to access to the Apple App Store. Here is a link with more details.
In Android, there's a setting named "Allow access to all apps in Google Play Store", when it is configured as Not configured, all apps not explicitly allowed for the user will be removed from the device.
To control app sign in access, condition access policy which Rahul mentioned is a good option. You can go through it to see if it can give you some thoughts.
https://learn.microsoft.com/en-us/entra/identity/conditional-access/overview
Hope the above information can help.
If the answer is helpful, please click "Accept Answer" and kindly upvote it. If you have extra questions about this answer, please click "Comment".
Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.