That’s a different threat model - the kids not wanting it blocked.
You can white list devices instead (so they’d have to spot a particular mac address), you can just add them to a different vlan in a different ssid (sane as you separate your IoT shit from your normal network), but you have to look at them establishing vpn to take traffic
In this case the user wants it blocked and wants to fight the their device which acts against them (google doesn’t want you blocking google services)
You can white list devices instead (so they’d have to spot a particular mac address), you can just add them to a different vlan in a different ssid (sane as you separate your IoT shit from your normal network), but you have to look at them establishing vpn to take traffic
In this case the user wants it blocked and wants to fight the their device which acts against them (google doesn’t want you blocking google services)