PL-900 Practice Question: Manage the Microsoft Power Platform environment
A company uses Power Automate flows that connect to SharePoint and Microsoft Entra ID. The administrator needs to ensure that the flows can access data only from approved data sources. What should the administrator configure?
⚠ Common exam trap
Many candidates confuse DLP policies with SharePoint permissions or connector sharing, thinking that restricting user access to SharePoint sites is sufficient to control flow data sources, when in fact DLP policies are the only mechanism that can restrict which connectors a flow can use at the environment level.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Data Loss Prevention (DLP) policy that restricts connectors to approved data sources
Data Loss Prevention (DLP) policies in the Power Platform allow administrators to control which connectors can be used together in flows and apps, effectively restricting flows to approved data sources like SharePoint and Microsoft Entra ID. By classifying connectors as Business or Non-Business, DLP policies prevent unauthorized data sharing between environments, which directly addresses the requirement to limit data access to approved sources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Define SharePoint site permissions for the flows
Why it's wrong here
SharePoint site permissions control which users and identities can read or write content, not which connectors a flow may invoke across services. It is tempting because it limits data exposure, but the requirement is source-level governance across SharePoint and Microsoft Entra ID connectors, which only a data policy enforces.
- ✓
Create a Data Loss Prevention (DLP) policy that restricts connectors to approved data sources
Why this is correct
A Data Loss Prevention policy in Power Platform classifies connectors into business, non-business and blocked groups, preventing flows from combining approved and unapproved data sources. This enforces the restriction to approved sources across SharePoint and Microsoft Entra ID connectors.
- ✗
Configure data policies in Power Apps settings
Why it's wrong here
Data policies in Power Apps settings are configured within the Power Platform admin centre and apply tenant-wide or per-environment; the stem asks for Power Automate flow governance, so the policy must be set for the Power Automate environment, not Power Apps settings. It is tempting because both surfaces expose DLP controls.
- ✗
Set connector sharing permissions to limit access
Why it's wrong here
Connector sharing permissions govern who may use a connector, not which data sources flows may reach; they cannot restrict endpoints to an approved list. It is tempting because sharing controls feel like governance, but the correct mechanism is a data policy (DLP) defining approved and blocked connectors per environment.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.