Courseiva
Extend Customer Service →hardMultiple Choice

MB-230 Extend Customer Service Practice Question

You are extending a Dynamics 365 Customer Service environment by creating a custom channel integration using the Direct Line Bot Framework. You need to ensure that when a customer sends a message, the bot can retrieve the customer's case history from Dynamics 365 and include it in the response. Which component must you configure to allow the bot to access Dynamics 365 data securely?

⚠ Common exam trap

The trap here is assuming that a Power Automate custom connector or a Power Virtual Agents bot inherently provides secure, direct access to Dynamics 365 data without explicit Microsoft Entra ID application registration and permissions.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

An Microsoft Entra ID application registration with appropriate API permissions to Dynamics 365, and configure the bot to authenticate using its client ID and secret.

The bot must authenticate to Dynamics 365 using an Microsoft Entra ID application registration with appropriate API permissions. This allows the bot to obtain an access token and call the Dynamics 365 Web API to retrieve case history. Other options either do not provide direct access, use unsupported authentication, or assume automatic access without configuration.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A Power Virtual Agents bot that is natively integrated with Dynamics 365, using the built-in authentication without additional configuration.

    Why it's wrong here

    Power Virtual Agents bots can integrate with Dynamics 365, but they do not automatically have access to case history without configuring authentication and permissions. The built-in integration typically requires the bot to be registered as an application user and granted security roles. Simply using a Power Virtual Agents bot does not bypass the need for secure authentication and authorization to Dynamics 365 data.

  • ✓

    An Microsoft Entra ID application registration with appropriate API permissions to Dynamics 365, and configure the bot to authenticate using its client ID and secret.

    Why this is correct

    To allow the bot to access Dynamics 365 data securely, you must register an application in Microsoft Entra ID, grant it API permissions to Dynamics 365 (such as user impersonation or application user), and configure the bot to authenticate using the application's client ID and secret. This enables the bot to obtain an access token and call the Dynamics 365 Web API. This is the standard secure method for server-to-server integration.

  • ✗

    A custom connector in Power Automate that uses the Dynamics 365 connector with OAuth 2.0 authentication.

    Why it's wrong here

    A custom connector in Power Automate can access Dynamics 365 data, but it is not directly used by the bot to retrieve case history during a conversation. The bot would need to call a Power Automate flow, which introduces additional latency and complexity. While secure, this approach is indirect and does not provide the bot with direct, real-time access to Dynamics 365 data within the bot's logic.

  • ✗

    A Dynamics 365 connection string stored in the bot's configuration file, using SQL authentication.

    Why it's wrong here

    Dynamics 365 does not support direct SQL authentication from external applications; it uses OAuth 2.0 via Microsoft Entra ID. Storing a connection string with SQL credentials is not only insecure but also technically impossible for accessing Dynamics 365 data. The platform's Web API requires bearer tokens obtained through Microsoft Entra ID. This option is a distractor based on on-premises database access patterns.

About these practice questions

Courseiva writes every MB-230 question from scratch — 189 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This MB-230 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the MB-230 exam.