I see that you can manually create a list of updates allowed to install, however I am looking for the most efficient way to only prevent one particularly bad update from being install on all machines in a batch.
You have two options. Either create a list of updates to install that includes all but the one update, or use the “hide” action to hide the one bad update. Once it has been hidden, you can install all remaining updates visible updates with the normal “download and install updates” action. See Method 1 and Method 2 outlined here: