Courseiva

PL-900 Practice Question: Describe the business value of Microsoft Power Platform

A healthcare provider needs to ensure that only authorized users can access patient data in a Power Apps app. The app uses Dataverse. What should the administrator configure?

⚠ Common exam trap

PL-900 often tests the distinction between authentication (Entra ID conditional access) and authorization (Dataverse security roles) — candidates who pick conditional access confuse controlling who can sign in with controlling who can access specific data.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign Dataverse security roles to users

Dataverse uses its own security model based on security roles, which define the privileges a user has on tables, records, and other resources. To ensure that only authorized users can access patient data in a Power Apps app that uses Dataverse, the administrator must assign appropriate Dataverse security roles to users. These roles control create, read, write, delete, and append privileges at the organization, business unit, parent-child business unit, and user levels.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure SharePoint permissions for the app

    Why it's wrong here

    SharePoint permissions govern SharePoint lists and libraries, not Dataverse tables, so they cannot restrict access to patient records stored there. It is tempting because SharePoint integration appears throughout Power Platform, and configuring site permissions would be right when an app's data actually resides in SharePoint lists rather than Dataverse.

  • ✗

    Set environment as restricted in Power Platform admin center

    Why it's wrong here

    Restricting an environment controls which makers can create apps and which connectors are available, not row-level access to Dataverse patient records. It is tempting as a broad lockdown, but the correct control is Dataverse security roles combined with table permissions, which govern record access per user.

  • ✗

    Use Microsoft Entra ID conditional access policies

    Why it's wrong here

    Conditional access governs authentication and sign-in risk, not row- or table-level authorisation inside Dataverse. It cannot restrict which patient records a signed-in user reads. It is tempting because it genuinely secures app access at the identity layer, and would be right for enforcing MFA or blocking risky sign-ins, but Dataverse security roles and business units control data access here.

  • ✓

    Assign Dataverse security roles to users

    Why this is correct

    Assigning Dataverse security roles grants users the precise privileges required to access patient records, satisfying the requirement that only authorised users reach the data. Security roles operate at the environment and table level, controlling create, read, update and delete permissions, so unauthorised users without an assigned role are denied access entirely.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.