If your firewalls do not support DNS-based filtering, it's time to act, this is old news, it's not an excuse anymore.
Or ask your network teams if they actually don't support it, or they just don't realize it's a feature now. IP-based allowlisting doesn't work with most cloud.