Which setting in CAPolicy1 should you modify to meet the finance department's technical requirements?
Choose an answer
Tap an option to check your answer.
Correct answer: Session.
Why this is the answer
The correct answer is Session. Session controls in Azure AD Conditional Access allow you to enforce restrictions within a cloud app, such as requiring a compliant device, enforcing app-enforced restrictions (like blocking downloads), or using Microsoft Defender for Cloud Apps for real-time monitoring and control. This directly addresses the finance department's need for technical controls beyond simple access, such as preventing data exfiltration or enforcing specific app behaviors. Cloud apps or actions defines which applications the policy applies to, not the specific controls within them. Conditions define when the policy applies (e.g., user risk, device platform, location). Grant determines whether access is allowed and if additional requirements (like MFA or compliant devices) are needed before access, but doesn't manage in-session behavior.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed