There might be situations while configuring or managing an application where you don't want tokens to be issued for an application. Or, you might want to block an application that you don't want your employees to try to access, like the deprecated Azure AD PowerShell modules (AppID 1b730954-1685-4b74-9bfd-dac224a7b894). To block user access to an application, you can disable user sign-in for the application, which prevents all tokens from being issued for that application.
Include a test group of users for each policy, but not both. If a user is included in both policies, or any policy with both conditions, the user has to satisfy MFA during sign-in. They also have to satisfy the custom control, which makes them redirected to the external provider a second time.