- Pure exclusions : Try to find exact matching policies that include exclusion
- Exclusions by inclusion: Try to find exact match for the exclusion created by inclusion (in order for mutations to be created these exclusions like apps and locations, need to be injected in the pipeline)
- Try to find catch-all policy when 1,2 cannot satisfy the pipeline
There can be situation, where the gap is created by combination of policies, in these cases the all permutations need to be used to do lookup of matches.
Ensure policies that target just devices are /can be filtered out Remove Security Information registration policies
add AZ CLI "piggyback"
Done