Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

A Power Platform administrator discovers that a developer has deployed a canvas app to production that connects to both SharePoint and an unapproved third-party REST API using a custom connector. The security team requires that custom connectors be reviewed before production use, while still allowing makers to prototype them in a sandbox environment. What should the administrator configure to meet this requirement?

⚠ Common exam trap

The trap here is assuming DLP policies are always tenant-wide, when they can actually be scoped to specific environments, which is exactly what allows blocking a connector in production while permitting it in a sandbox.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it

Data Loss Prevention policies can be scoped to individual environments, allowing the administrator to block the custom connector in production while a separate policy permits it in the sandbox. This enforces the security team's review requirement without eliminating prototyping. A tenant-wide block, role removal, and tenant-level connector consent do not provide the environment-specific control needed, and some do not affect the already deployed app.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Environment security roles that remove the Environment Maker role from the developer in production

    Why it's wrong here

    Removing Environment Maker prevents the developer from creating new resources but does not stop the already deployed app from using the custom connector. It also penalizes the developer rather than governing the connector itself. The requirement is to control custom connector usage, not to revoke a user's building privileges.

  • ✓

    A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it

    Why this is correct

    DLP policies can be scoped to specific environments, so the custom connector can be Blocked in production while a different policy allows it in the sandbox. This prevents the unapproved connector from running in production yet preserves prototyping capability. It directly matches the requirement to review custom connectors before production use while allowing sandbox experimentation.

  • ✗

    Connector consent settings that require admin approval for the custom connector tenant-wide

    Why it's wrong here

    Connector consent settings govern whether makers can use a connector that has not been approved for the tenant, but they apply at the tenant level rather than per environment. They also do not block an already deployed app that has obtained consent. This does not achieve the environment-specific production block the security team requires.

  • ✗

    A tenant-wide DLP policy that places the custom connector in the Blocked group for all environments

    Why it's wrong here

    A tenant-wide policy would block the custom connector everywhere, including the sandbox, which removes the makers' ability to prototype. The requirement explicitly allows sandbox use while restricting production. While secure, this approach is overly broad and fails to preserve the prototyping capability the security team wants to keep.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.