Make sure that Enable SSL Inspection and Application Firewall options are enabled on General tab of POLICY | DPI-SSL > Client SSL. For more information, refer to Configuring General DPI-SSL/TLS Client Settings.
To filter HTTPS and SSL-based traffic by app rules using DPI-SSL
Configure an HTTP Client policy to block Microsoft Internet Explorer browser with block page as an action for the policy.
Here is an example to configure a match object and set the action for the app rule policy. But you can configure and set the action in other ways to allow or block the content.