A global organization uses Power Platform with Microsoft Dataverse as the data source. They need to ensure that users in different regions only see data relevant to their region. What should they implement?
Dataverse security roles grant privileges at the table and record level, and row-level security restricts each user to records matching their region. This satisfies the requirement that users in different regions see only their own regional data, unlike column-level or field-level controls.
Why this answer
Microsoft Dataverse supports row-level security through security roles, which can be combined with teams and business units to restrict records so users only see data relevant to their region. Security roles define privileges at the table level, and row-level filtering is achieved by assigning users to business units or teams that own the records. This is the native, supported way to enforce regional data isolation in Power Platform.
Exam trap
PL-900 often tests the confusion between app-level permissions and data-level security — candidates pick 'app permissions' thinking it controls data visibility, when Dataverse row-level security is the correct mechanism.
How to eliminate wrong answers
Option A is wrong because Power Apps app permissions control who can access the app itself, not which rows of data they can see within Dataverse. Option B is wrong because Power Automate conditional logic can branch workflows but does not enforce data visibility at the Dataverse row level. Option D is wrong because Power BI dashboard filters only affect visualization, not the underlying data access or security in Dataverse.