Operators reach production through the Azure portal, Azure CLI, and PowerShell, and MFA must cover that management plane. Which Conditional Access cloud app target is appropriate?
Select an answer to reveal the explanation.
Short Explanation
Aim the MFA policy at the Azure management app—Windows Azure Service Management API—not at “all of Microsoft 365.” Portal, CLI, and PowerShell talking to Azure Resource Manager show up under that management-plane target.
Full Explanation
Conditional Access policies that protect Azure resource management should include the Windows Azure Service Management API cloud app (or the corresponding Azure Government management app). Targeting Microsoft 365 apps does not reliably cover Azure portal, CLI, and PowerShell management of Azure resources.