Hello rr-4098,
It depends on the scenario.
If you are looking for removing the inbound on certain devices only, you need to have 2 policies for allow and block and assigned groups should contain the intended devices.
If you are looking for flexibility in changing the rules for all targeted devices, try the reusable groups.
Refer to: Use reusable groups of settings policies in Microsoft Intune - Microsoft Intune | Microsoft Learn
Hope this helps!
If you found the information above helpful, please Click Yes. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.