Does not sound very kosher though. for example, why block that URI, if in fact you think they should not be allowed to use any Internet service at all?
Anyways, so you can manage for all http traffic from these client to come to your F5s? how do you do that? F5 LTM is the gateway?
In order to use an iRule like suggested, you would need a virtual server listening on an IP that those clients would connect to... you could try and just make that IP the actual Microsoft IP address.. is there only one? what if it changes?
If you can control the clients, it might be simpler to update their /etc/hosts to point the DNS name to loopback.