You have a Microsoft 365 ES subscription that user Microsoft Defender for Cloud Apps and Yammer.
You need prevent users from signing in to Yammer from high-risk locations.
What should you do in the Microsoft Defender for Cloud Apps portal?
Correct Answer: A
Defender for Cloud Apps (MCAS) provides Access policies to control sign-in and session access to sanctioned apps based on conditions such as user, device, and location. SC-300 notes that access policies can allow, block, or require additional controls and are evaluated at sign-in, making them appropriate to prevent logons from risky or specific locations. In contrast, Activity policies alert on or govern in-app actions (downloads, sharing) after sign-in, and Anomaly detection policies use heuristics to surface suspicious behavior, not enforce blocking. "Unsanctioning" an app merely flags it and can integrate with firewall/proxy tagging; it does not directly enforce a conditional sign-in block. Therefore, to block Yammer sign-ins from high-risk locations, you create an Access policy in Defender for Cloud Apps targeting Yammer with a condition for the designated high-risk locations and set the action to Block (or require step-up).