Courseiva

PL-900 Practice Question: Describe the business value of Microsoft Power Platform

A global organization uses Power Platform with Microsoft Dataverse as the data source. They need to ensure that users in different regions only see data relevant to their region. What should they implement?

⚠ Common exam trap

PL-900 often tests the confusion between app-level permissions and data-level security — candidates pick 'app permissions' thinking it controls data visibility, when Dataverse row-level security is the correct mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Dataverse security roles with row-level security

Microsoft Dataverse supports row-level security through security roles, which can be combined with teams and business units to restrict records so users only see data relevant to their region. Security roles define privileges at the table level, and row-level filtering is achieved by assigning users to business units or teams that own the records. This is the native, supported way to enforce regional data isolation in Power Platform.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Power Apps app permissions

    Why it's wrong here

    Power Apps app permissions govern who may open or edit an app, not which Dataverse rows they retrieve; region-based visibility requires Dataverse security roles with row-level filtering. It is tempting because app sharing controls are correct when the requirement is limiting access to specific apps rather than to data records.

  • ✗

    Power Automate conditional logic

    Why it's wrong here

    Power Automate conditional logic branches a flow's actions at runtime; it cannot restrict which Dataverse records a user queries, so it enforces no data visibility. It is tempting because conditions are correct when the requirement is routing or filtering automated process steps based on a field value such as region.

  • ✓

    Dataverse security roles with row-level security

    Why this is correct

    Dataverse security roles grant privileges at the table and record level, and row-level security restricts each user to records matching their region. This satisfies the requirement that users in different regions see only their own regional data, unlike column-level or field-level controls.

  • ✗

    Power BI dashboard filters

    Why it's wrong here

    Power BI dashboard filters only restrict what a report visual displays; they do not enforce row-level security on Dataverse records, so users could still retrieve other regions' data through apps or APIs. It is tempting because Power BI row-level security is correct for restricting report data by region.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on PL-900

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. An organization plans to deploy a Power Platform solution that uses Dataverse as the data source. They need to ensure that users can only see records from their own department. What should they implement?

hard
  • A.Power Automate to filter records
  • B.Audit logging
  • C.Column-level security profiles
  • ✓ D.Business units and security roles with team-based access

Why D: Business units and security roles with team-based access are the correct implementation because Dataverse uses a hierarchical security model where business units define the organizational structure and security roles control record-level permissions. By configuring business units per department and assigning users to teams within those units, you can enforce that users only see records belonging to their own department through record ownership and sharing rules.

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.