* Only users in the finance department must be able to sign in to an Azure AD enterprise application named App1. All other users must be blocked from signing in to App1. One Policy. * Only users in the R&D department must be blocked from signing in from both Android and iOS devices. One Policy. * Users must only be able to sign in from outside the corporate network if the sign-in originates from a compliant device. All users must use multi-factor authentication (MFA) when they sign in from outside the corporate network. One policy * All users must be blocked from signing in from outside the United States and Canada. Only users in the R&D department must be blocked from signing in from both Android One Policy Reference: https://learn.microsoft.com/en-us/azure/active-directory/conditional-access/plan-conditional-access