You are absolutely on the right track with the first policy you found. Enabling the setting to not connect to any Windows Update internet locations is the exact graphical equivalent of the registry modification I previously mentioned, and applying it will enforce the strict offline boundary your environment requires. Disabling the optional updates policy you also found is good practice for managing what end users can see, but it does not control how the underlying servicing stack behaves when it attempts to repair components or map payloads during cumulative updates.
Regarding the optional component installation policy you could not locate, it is very common to overlook it because it is not contained within any subfolder. Once you expand Administrative Templates, you must click directly on the System folder itself, and then scroll through the long alphabetical list of settings that populates in the right hand pane. You will find the policy named exactly as specify settings for optional component installation and component repair. Opening that policy will allow you to explicitly prevent the system from downloading payloads from Windows Update, ensuring your offline machines rely entirely on your WSUS infrastructure and never attempt those doomed outbound internet connections during your 25H2 deployments.
VPHAN