PL-900 Practice Question: Manage the Microsoft Power Platform environment
A multinational corporation uses Power Platform extensively. They have multiple environments: DEV, TEST, UAT, STAGING, and PROD. A developer accidentally published a Power App that connects to a SQL Server database using an unapproved connector in the PROD environment. The organization has strict data governance policies that require all connections to use approved connectors only. The admin needs to block this connector in PROD while still allowing it in other environments. What should the admin do?
⚠ Common exam trap
The trap is defaulting to a tenant-level DLP policy because it's the most familiar control; candidates overlook that environment-level policies are required when governance must differ between PROD and non-PROD environments.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create an environment-level DLP policy for PROD that blocks the connector.
Environment-level DLP policies in Power Platform apply only to a specific environment, so creating one for PROD that blocks the unapproved connector restricts it there while leaving DEV, TEST, UAT, and STAGING unaffected. This precisely meets the requirement to block the connector only in PROD. Tenant-level policies would affect all environments, which is too broad.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a tenant-level DLP policy that blocks the connector for all environments.
Why it's wrong here
A tenant-level DLP policy applies across every environment, so it would also block the connector in DEV, TEST, UAT and STAGING, contradicting the requirement to allow it there. Tenant-wide policies are correct when the connector must be prohibited everywhere in the organisation.
- ✗
Remove the developer's permissions to the PROD environment.
Why it's wrong here
Revoking the developer's PROD permissions stops that individual, but the connector remains permitted for every other maker in PROD. Removing environment access is correct when a specific user must be excluded, not when a connector must be blocked environment-wide.
- ✗
Delete the Power App from PROD.
Why it's wrong here
Deleting the app removes the artefact but leaves the unapproved connector itself available in PROD, so another maker could recreate the same connection. Deleting apps is correct for removing obsolete or unwanted apps, not for enforcing connector governance.
- ✓
Create an environment-level DLP policy for PROD that blocks the connector.
Why this is correct
Environment-level DLP policies scope connector blocking to a single environment, so PROD can block the unapproved SQL connector while DEV, TEST, UAT and STAGING remain unaffected. Tenant-level policies would apply everywhere, failing the requirement to allow it elsewhere. This satisfies the stem's constraint of blocking in PROD only.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.