Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

A company uses Microsoft Power Platform and wants to enforce data loss prevention (DLP) policies for all environments. The admin needs to block the use of SharePoint connector in all default environments. Which action should the admin take?

⚠ Common exam trap

It's easy for candidates to confuse DLP policies with other security controls like conditional access or connector sharing settings, mistakenly thinking those can block connector usage at the environment level.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a DLP policy that applies to all environments and block the SharePoint connector.

DLP policies in Microsoft Power Platform are designed to control connector usage across environments. By creating a DLP policy that applies to all environments and blocking the SharePoint connector, the admin ensures that the connector is prohibited in every environment, including all default environments. This action directly enforces the data loss prevention requirement at the tenant level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a DLP policy and assign it to the default environment only.

    Why it's wrong here

    A DLP policy scoped to the default environment alone leaves other default environments ungoverned, so the requirement to block SharePoint everywhere is unmet. Environment-specific policies are correct when only one environment needs distinct connector rules, not tenant-wide enforcement.

  • ✗

    Use Microsoft Entra ID conditional access to block the SharePoint connector.

    Why it's wrong here

    Microsoft Entra ID conditional access evaluates user sign-in signals such as device compliance and location; it cannot block a Power Platform connector, which is governed by DLP policy classification. Conditional access is correct for controlling access to cloud apps, not connector usage.

  • ✓

    Create a DLP policy that applies to all environments and block the SharePoint connector.

    Why this is correct

    A tenant-wide DLP policy scoped to all environments blocks the SharePoint connector across every default environment, satisfying the requirement to enforce restrictions everywhere rather than per-environment. Connector classification as Blocked prevents makers from adding it to apps and flows, which per-environment policies could not achieve at this scale.

  • ✗

    Configure connector sharing settings in Power Apps to block SharePoint.

    Why it's wrong here

    Connector sharing settings in Power Apps govern which makers may share a connection with other users; they do not restrict a connector's use across environments. That control is correct for limiting connection reuse by individual makers, not for tenant-wide connector blocking.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.