PL-900 Practice Question: Manage the Microsoft Power Platform environment
A Power Platform administrator is reviewing the security roles in a new environment. The administrator needs to grant a user the ability to create and modify all components within the environment, including managing other users' security roles. Which security role should be assigned?
⚠ Common exam trap
A common mix-up: candidates confuse the System Customizer role with the System Administrator role, as both can modify components, but only System Administrator can manage security roles.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
System Administrator.
The System Administrator security role in a Power Platform environment grants full control over all components and settings, including the ability to manage security roles for other users. It is the only role among the options that provides this level of administrative access within the environment. The Environment Maker and System Customizer roles have more limited permissions, and Delegated Administrator is a tenant-level role, not an environment-level one.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
System Customizer.
Why it's wrong here
The System Customizer role allows users to customize the environment, such as creating and modifying entities, forms, and views, but it does not grant the ability to manage security roles or administer users. It is more limited than the System Administrator role and does not meet the requirement to manage other users' security roles.
- ✗
Delegated Administrator.
Why it's wrong here
Delegated Administrator is not a standard security role within a Power Platform environment. It is a role in the Power Platform admin center that allows users to manage environments and settings at the tenant level, but it does not directly grant permissions within an environment to manage components or security roles. It is not the appropriate role for this scenario.
- ✓
System Administrator.
Why this is correct
The System Administrator security role provides full permissions to manage all components in the environment, including creating and modifying entities, managing security roles, and administering users. It is the highest level of access within an environment and meets the requirement to manage other users' security roles and all components.
- ✗
Environment Maker.
Why it's wrong here
The Environment Maker role allows users to create apps, flows, and other resources, but it does not grant the ability to manage security roles or administer the environment. It is limited to creating and sharing resources, not to full administrative control. Therefore, it does not meet the requirement to manage other users' security roles.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.