It very much is possible to ban "all" public and even commercial VPNs. VPN traffic tends to have very distinct characteristics in logs and it is not overly difficult for orgs to get the IP ranges allocated to each company.
What is not possible is banning all vpn traffic in the sense that a friend or family member sets up wireguard for you. But that is a drop in the bucket to the point of being functionally nonexistent.
The middle ground, of course, are pseudo-botnets of compromised computers. But those also tend to be a fairly small percentage (outside of DDOSing) and are likely getting blocked for other reasons.