What you need should work this way:
1-Create your webfilter profile. Only allow what you need, and block the rest.
2-Create a rule, Source: ALL, Dest: ALL, Access Policy: Allow, Filter: The one you created. Authentication: User/Group, depends on your NTLM settings
3-This is not necessary, but just in case. Create a second rule to deny ALL, on 2nd position.
4-Apply changes.
I must warn you that standard urlfilters on Endian Firewall are very basic, it doesn't catch a lot.
If you need updated urlfilters you should check for better filters and replace the ones in /var/signatures/urlfilter/blacklists.
What I did some time ago was to add many different urlfilters to endian.
For example, download new url filters from
http://www.urlblacklist.com/ (only once for free!!),
http://www.shallalist.de/ or others, and replace the files on blacklist. Don't delete, just replace or add new ones.