The problem with Windows firewall is that there is no order to the rule processing, so you need to make sure you don't have a conflicting rule that could be triggered. So you'll need to remove any http,https rules that exist that would allow the outbound traffic
You may want to change the default outbound rule to block instead of allow.
For the admin group you'll need to create a few rules.
- They will all be Custom rule types
- Programs should be all.
- You'll need a rule for TCP and UDP (seperate rules with the remote ports specified 80,443 and 8443), local should be all
- Scope would be any any
- Action Allow if secure > allow the connection to use null encapsulation
- Computers > Only allow connections to these...