um ACKSHUALLY you can disable Windows Update competely by setting group policies to disable automatic updates and specify a custom URL for Windows Update and point it to nothing. There a few other local group policies you can configure to further prevent updates, just open the Local Group Policy Editor and go to Computer/Administrative Templates/Windows/Windows Update (or something like that, look for Windows Update under Computer Administrative Templates).
I know this because literally yesterday I had to undo all of that so I could download something from the Microsoft Store (doing this also prevent MS Store apps from downloading)
Windows Firewall is what you are looking for. In Windows firewall you add rules per process and can block them from accessing all networks.