PL-900 Practice Question: Manage the Microsoft Power Platform environment
A company uses Microsoft Power Platform and wants to allow external users (guests) to access a canvas app. The app connects to a Dataverse database that contains sensitive customer information. The security team is concerned about data leakage. What should the administrator do to minimize risk?
⚠ Common exam trap
Many candidates assume adding guests via Microsoft Entra ID and applying DLP policies is sufficient, but they overlook that guests in the same environment inherit the same Dataverse database access unless explicitly restricted, which is harder to manage and audit than a dedicated environment.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a new environment specifically for external users with only the required data.
Creating a separate environment for external users allows the administrator to control exactly which Dataverse tables and data are exposed, minimizing the risk of sensitive customer information being leaked. This approach follows the principle of least privilege by isolating guest access to a sandboxed environment with only the required data, rather than granting access to the existing production environment.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable sharing of the app with external users.
Why it's wrong here
This prevents the business requirement of allowing external access.
- ✓
Create a new environment specifically for external users with only the required data.
Why this is correct
This isolates the sensitive data and provides controlled access.
- ✗
Add external users as guests in Microsoft Entra ID and grant them access to the existing environment.
Why it's wrong here
This exposes sensitive data to external users in the same environment.
- ✗
Use DLP policies to block all connectors except the canvas app.
Why it's wrong here
DLP policies do not prevent external users from accessing data within Dataverse.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 904 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.