DoH makes the request look like a regular HTTPS request, therefore you'd need more sophisticated heuristics to block it.
If you contend that you can match the DoH SNI with a known DoH server and block that, fair enough. However, there's always another unknown DoH server you haven't blocked. Blocking DoT is trivial in comparison, because of its signature on the wire.