The app policies are for the apps that your end users have authorized Oatuh tokens.
There are three types of app categories:
One is for critical risk and unsanctioned apps: 00:22
The second is for VPN and explicit apps: 00:32
The third app category is for apps with abnormal permission/email policies: 00:43
How to turn on remediation (revoke access to break the OAuth token/warn users): 01:10
Take control of applications and set the name of the policy after the name of the app: 01:50
How to set up a policy around a category of apps, for example, games: 02:35
Narrowing down your policy types with scope categories, such as access into emails and/or drive: 02:55
Setting up an app policy based on risk level: 03:25
How to set up a policy based on a specific user, group, or OU: 03:50