PL-900 Practice Question: Manage the Microsoft Power Platform environment
A Power Platform administrator discovers that a developer has deployed a canvas app to production that connects to both SharePoint and an unapproved third-party REST API using a custom connector. The security team requires that custom connectors be reviewed before production use, while still allowing makers to prototype them in a sandbox environment. What should the administrator configure to meet this requirement?
⚠ Common exam trap
The trap here is assuming DLP policies are always tenant-wide, when they can actually be scoped to specific environments, which is exactly what allows blocking a connector in production while permitting it in a sandbox.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it
Data Loss Prevention policies can be scoped to individual environments, allowing the administrator to block the custom connector in production while a separate policy permits it in the sandbox. This enforces the security team's review requirement without eliminating prototyping. A tenant-wide block, role removal, and tenant-level connector consent do not provide the environment-specific control needed, and some do not affect the already deployed app.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Environment security roles that remove the Environment Maker role from the developer in production
Why it's wrong here
Removing Environment Maker prevents the developer from creating new resources but does not stop the already deployed app from using the custom connector. It also penalizes the developer rather than governing the connector itself. The requirement is to control custom connector usage, not to revoke a user's building privileges.
- ✓
A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it
Why this is correct
DLP policies can be scoped to specific environments, so the custom connector can be Blocked in production while a different policy allows it in the sandbox. This prevents the unapproved connector from running in production yet preserves prototyping capability. It directly matches the requirement to review custom connectors before production use while allowing sandbox experimentation.
- ✗
Connector consent settings that require admin approval for the custom connector tenant-wide
Why it's wrong here
Connector consent settings govern whether makers can use a connector that has not been approved for the tenant, but they apply at the tenant level rather than per environment. They also do not block an already deployed app that has obtained consent. This does not achieve the environment-specific production block the security team requires.
- ✗
A tenant-wide DLP policy that places the custom connector in the Blocked group for all environments
Why it's wrong here
A tenant-wide policy would block the custom connector everywhere, including the sandbox, which removes the makers' ability to prototype. The requirement explicitly allows sandbox use while restricting production. While secure, this approach is overly broad and fails to preserve the prototyping capability the security team wants to keep.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.