> Is it possible to control Store apps in the same way from Intune?
The end user experience as far as control goes is no different. As long as you properly block the Microsoft Store App (by using the policy to allow only the private store) then only apps that you the admin assign to managed device will be available for the end-user to install from the Store (the Store app itself won't show anything).
You can't directly prevent the usage of WinGet from a command-line today although we have an item in the backlog to address this. While this is certainly a hole for us to address and we shouldn't rely on obscurity, for now, this is somewhat of a small hole as how many users would actually do this? Also, this is no different than a user running any exe (portable or otherwise) as there's nothing to prevent this either in standard scenarios unless you've embraced WDAC or AppLocker and implemented allow-listing (which you should do as this is the most effective security tool available).