I'd say it's a much better idea to block/manage updates from the Windows side using something like group policy and WSUS.
Assuming that L7 rule is applied correctly but is just not capturing Windows Update traffic for whatever reason, you could look at blocking the specific domains instead.
Ajit's comments in the following thread are pretty good at outlining the options.
How to block Windows Updates? - The Meraki Community