You have a Microsoft 365 E5 subscription that uses Microsoft Defender for Cloud Apps and Conditional Access policies. You need to block access to cloud apps when a user is assessed as high risk.
Which type of policy should you create in the Microsoft Defender for Cloud Apps?
Correct Answer: C
According to the Microsoft SC-300 Study Guide and Microsoft Defender for Cloud Apps documentation, an access policy in Microsoft Defender for Cloud Apps (MCAS) enables administrators to enforce real-time session control and conditional access based on user risk or session context. These policies integrate directly with Azure AD Conditional Access and Microsoft Defender for Identity signals to determine when a user's session should be allowed, monitored, or blocked.
The documentation specifies:
"Access policies are used to control user access and session activities in real-time. You can use these policies to block access, require session control, or limit downloads when risk conditions such as 'user risk = high' are detected." In this case, since the requirement is to block access to cloud apps when a user is assessed as high risk, an access policy in Defender for Cloud Apps must be used. Other options are not applicable because:
* OAuth app policy controls permissions granted to third-party apps.
* Anomaly detection policy detects unusual activities but does not block access.
* Activity policy monitors specific user actions within apps.