You can use the MX firewall for inter-vlan firewalling too if it's the L3 device routing between subnets.
Basically you setup a rule that blocks all access to the IP address in the L3 firewall settings in Firewall & SD-WAN > Firewall.
And then you indeed define a group policy in Network-Wide > Group Policies that has specific L3 firewall rules for that special group of people and assign it to them. Keep in mind that this will only work if the destination IP address you're blocking access to is on a different subnet than the source subnet the clients are on.
If the special group of people are on their own VLAN you could use the regular firewall. Just add another rule with the source subnet set.