A company uses Azure AD and wants to enforce that any application requesting access to Microsoft Graph must be pre-approved by an administrator rather than consented to by users. How should this be configured?
-
A
Disable user consent for all applications and require admin consent workflow
-
B
Configure Conditional Access for application consent
-
C
Use PIM to gate API permissions
-
D
Set application access policies in Exchange Online