An organization wants to mandate that all pipelines include a security scanning job. Which Azure DevOps feature best enforces this?
-
A
Branch policies
-
B
Required pipeline templates via the `extends` keyword and protected template resources
-
C
Variable group permissions
-
D
Service connection approvals