A healthcare organization must ensure that sensitive patient data is protected under Zero Trust even when accessed by authorized users on compliant devices. Which additional control should be applied?
-
A
Allow all access once device compliance is confirmed
-
B
Apply data-level encryption and sensitivity labels using Microsoft Purview Information Protection
-
C
Remove conditional access policies for compliant devices
-
D
Grant permanent access tokens after initial authentication