
Explanation:
Box 1: Exact data match (EDM)
To trigger a Microsoft Defender for Cloud Apps session policy step-up authentication when a user downloads a document based on a predefined form, use the Data Classification Service (DCS) inspection method and select sensitive information type (SIT) or exact data match (EDM) as the inspection type. These options allow you to specify the type of sensitive information that should trigger the policy and potentially require step-up authentication.
Box 2: Authentication context
You will also need to define the authentication context in Microsoft Entra ID for the step-up authentication.
Reference:
https://learn.microsoft.com/en-us/defender-cloud-apps/dcs-inspection