If the devices are Samsung Knox Standard devices, we can refer to the following article to allow and block apps:
https://video2.skills-academy.com/en-us/mem/intune/configuration/samsung-knox-apps-allow-block
For other devices, if we only allow corporate work apps on a Fully Managed device, the public Play Store cannot be accessed to download personal apps. There is no need to set any policy. Same for the Work Profile section. However, if access to the public Play Store is allowed, we can try to add the app as uninstall to the Android devices to block it. The following link for the reference:
https://www.inthecloud247.com/how-to-block-mobile-apps-like-tiktok-with-microsoft-intune/
Note: Non-Microsoft link, just for the reference.
Hope it can help.