This is sorta it. SNI is the only unecrypted part that leaks the server hostname. CN/SAN blocking usually has a middlebox that decrypts the connections so there is nothing to be done here.
If somebody can MitM your encrypted connection to both server and DNS, encrypted SNI stops working to my understanding.