Yes, you can run `login` instead of a shell, but doing so require the tool to be executed as root, still sound bad.
I'd recommend to use a proxy that supports converting socket to Websocket(wss) and back, then you can by-pass the blockage from there. And since it's a proxy, it should not decrypt the SSH traffic.
The idea is basically:
Your SSH client <---SSH-Traffic---> Proxy front-end <----Websocket----> Proxy back-end <---SSH-Traffic---> Target SSH server
You can deploy the "Proxy front-end" inside the restricted network, and the "Proxy back-end" out side the network. After that, all you need to do it to config your SSH client to go through that proxy front-end.
There are many proxy software is capable of doing that, the GitHub keyword I believe is "socks5 websocket".