Blocking IPs is one way. What my college used to block protocol. Like openvpn (TCP) protocol was blocked throughout the network while over UDP it worked fine. Wireguard was also unblocked.
Also the firewall they used, fortigate, already allows blocking VPNs (using a server side list of IPs which are updated weekly i guess) so it depends on how they will have it setup.