I guess you are using HTTP Proxy ? So you can put them in the "URL blacklist" in your surf protection profile.
For example: windowsupdate.microsoft.com download.microsoft.com update.microsoft.com
If you don't use HTTP proxy, just add those servers as Network Definition (DNS hostname) Put them in a group "MS_Update_Servers" and add a rule like Internal_Network / HTTP / MS_Update_Servers / Deny Internal_Network / HTTPS / MS_Update_Servers / Deny