There are certain URLs that are not able to be blocked, as they may break your Confluence instance:
- /admin/*
- /download/*
- /images/*
- /plugins/servlet/upm
Blocking any of these will mean the user sees a "404 - Page not found" error (not a "No Permission" error). This way there is no information exposed about the existence of a function within your instance.