ZeroTrust with attachments in MS 365

How can we declare permitted Internet email attachment types while blocking the rest?

That article describes different scenarios using blocklists. How do I create a rule to specifically allow authorized attachment types and not allow anything else? None of the actions in the Rule Conditions say "Deliver the message as normal".