The "Filter Avoidance" content category will block encrypted DNS.
Personally, I turned off encrypted DNS in business environments (either via AD group policy or Intune). It reduces your ability to block threats at the perimeter a lot. The risk is not worth the privacy gained, in a business environment, for the vast majority of countries (however I do accept their are some oppressive regimes where encrypted DNS may be needed for safety).