Under Users>Include<Select Users and Groups, choose Directory Roles.
Configure highly privileged Directory Roles
End-User Impact
Level: Medium
Since this will be only scoped to privileged roles, the impact will be limited. The severity of impact is increased to medium since it does require the scoped users to reauthenticate once every time the user closes and reopens the browser.
Tips
This is a policy that you could scope additionally to guest users and for external access on personal devices that are not MDM or MAM enrolled.