PL-900 Practice Question: Manage the Microsoft Power Platform environment
An administrator is setting up a new Power Platform environment for a department. The department requires that all users in the environment use only approved connectors, and that data cannot be shared between the approved connectors and any unapproved connectors. What should the administrator configure?
⚠ Common exam trap
The trap here is assuming that environment security roles or conditional access can control connector usage, but only DLP policies provide that capability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A data loss prevention (DLP) policy that classifies connectors into Business, Non-Business, and Blocked groups.
Data loss prevention policies in Power Platform are designed to classify connectors and control data flow between them. By assigning approved connectors to the Business group and unapproved ones to Blocked, the policy ensures that only approved connectors are used and that data cannot be shared with unapproved ones. This is the correct and only native mechanism to enforce such restrictions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A Power Automate flow that monitors connector usage and alerts the administrator.
Why it's wrong here
A monitoring flow can provide alerts but does not prevent users from using unapproved connectors or sharing data between them. It is a reactive measure, not a preventive control. The requirement is to enforce restrictions, which a flow alone cannot achieve.
- ✗
Environment security roles that restrict which connectors users can access.
Why it's wrong here
Environment security roles control access to environments and resources within them, but they do not govern connector usage or data sharing between connectors. They cannot enforce which connectors are approved or prevent data mixing. Therefore, this option does not fulfill the requirement.
- ✓
A data loss prevention (DLP) policy that classifies connectors into Business, Non-Business, and Blocked groups.
Why this is correct
DLP policies allow administrators to classify connectors into Business, Non-Business, and Blocked categories. By placing approved connectors in the Business group and unapproved ones in Blocked, the policy prevents data sharing between them. This precisely meets the requirement to restrict usage to approved connectors and prevent data leakage.
- ✗
Microsoft Entra ID conditional access policies that block unapproved connectors.
Why it's wrong here
Conditional access policies in Microsoft Entra ID control access to resources based on conditions like user, device, and location, but they do not manage Power Platform connectors. They cannot classify or block specific connectors within Power Platform. Thus, they are not suitable for this scenario.
Go deeper
Related to this question
About these practice questions
One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.