While the graphic shows Entra, the same model is used for all Directory Services integrations.
These rules apply to public/private model access and context data.
Everyone will have the Default Policy applied to their traffic.
Configure additional groups as needed for different access to models and context data.