PL-900 Practice Question: Manage the Microsoft Power Platform environment
A small business wants to give its finance team a dedicated space to build apps and flows that only finance team members can access, separate from the default environment used by the rest of the company. The administrator needs to create this isolated workspace. What should the administrator create?
⚠ Common exam trap
A common mix-up: candidates confuse a solution, which packages components for deployment, with an environment, which is the actual security and isolation boundary for apps, flows, and data.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A new Power Platform environment with restricted user access
Power Platform environments are the fundamental security and isolation boundary. Creating a dedicated environment and granting access only to finance team members ensures their apps, flows, and data are separated from the default environment. Microsoft 365 groups, Dataverse tables, and solutions do not provide this isolation, since they either manage unrelated services, store data inside an existing environment, or package components for transport.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
A new Power Platform environment with restricted user access
Why this is correct
A Power Platform environment is the container that isolates apps, flows, connections, and Dataverse data. By creating a new environment and granting access only to finance team members, the administrator provides an isolated workspace. Security roles and environment-level access control who can build and use resources within it, matching the requirement exactly.
- ✗
A new Microsoft 365 group and assign it the Global Administrator role
Why it's wrong here
A Microsoft 365 group manages membership and shared resources like mailboxes and SharePoint sites, but it does not isolate Power Platform apps and flows. Assigning Global Administrator is an over-privileged tenant role unrelated to environment isolation. This approach neither creates a separate Power Platform workspace nor restricts access to finance users appropriately.
- ✗
A new Dataverse table with column-level security for finance data
Why it's wrong here
A Dataverse table stores data within an existing environment but does not create an isolated workspace for building apps and flows. Column-level security restricts access to specific columns, not to the apps and flows themselves. The finance team would still be working in a shared environment, so the isolation requirement is not met.
- ✗
A new Power Apps solution containing the finance team's apps
Why it's wrong here
A solution is a packaging and transport mechanism for apps, flows, and components; it does not provide a separate security boundary. Solutions are imported into environments, so they inherit the environment's access model. Creating a solution alone would not isolate the finance team's resources from the rest of the company.
Go deeper
Related to this question
About these practice questions
One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.