A company is using Power Automate flows that connect to multiple third-party services. The security administrator wants to ensure that no sensitive data is sent to unauthorized external services. Which feature should be used to enforce this requirement?
DLP policies in Power Platform define connector classification into Business, Non-Business and Blocked groups, then enforce which connectors a flow may combine. This directly prevents sensitive data reaching unauthorised external services, satisfying the administrator's requirement to block exfiltration across third-party connections.
Why this answer
Data Loss Prevention (DLP) policies in Power Platform define which connectors are Business, Non-Business, or Blocked, and prevent flows from combining connectors across groups — thereby stopping sensitive data from flowing to unauthorized external services. This is the purpose-built governance control for restricting connector usage across flows and apps.
Exam trap
The trap is confusing monitoring/auditing features (which detect after the fact) with preventive controls like DLP that actually block unauthorized connector combinations.
How to eliminate wrong answers
Option B is wrong because audit logging only records activity for later review; it does not prevent data from being sent to unauthorized services. Option C is wrong because environment routing rules govern how makers are directed to environments during creation, not connector-level data flow restrictions. Option D is wrong because Copilot is an assistive AI feature for authoring and does not enforce connector governance or DLP.