%windir%\* only affects the files in the %windir% directory while %windir%\*\* covers all the files in %windir% and in its folders, subfolders, sub-subfolders ...
So if you choose %windir%\*\* as an exclusion, blocking won't work because the access to all files is allowed.