Under the Zero Trust 'use least privilege access' principle, which Entra ID feature limits the blast radius of compromised application identities by granting only permissions required for a specific task?
-
A
Global Administrator role
-
B
App-only permissions scoped to minimum required Microsoft Graph scopes
-
C
Delegated permissions with admin consent for all scopes
-
D
Guest user access to the entire tenant