You want to block a particular client machine type (e.g Windows) in a UPE Cloud SWG tenant via CPL.
Installing below policy into Cloud SWG UPE policy would deny all windows machine. The ".substring" clause would match the word "windows" in the long OS string obtained when Cloud SWG receives the request.
<proxy>
client_context.os.substring="windows" deny