Earlier quoted context omitted.
DNS over TLS is just DoH but with an easily blocked separate port
Which is great from a local sysadmin perspective. With DoH I have no control of what various apps on devices on my devices are querying.
That's an intentional design feature. You're attempting to intercept traffic, and any mechanism you could use to do so "transparently" could be used by any hostile network to do so.
You can still intercept traffic from cooperating devices if you want, just not transparently. That's a feature, not a bug, and the Internet will be better for it.