PL-900 Practice Question: Manage the Microsoft Power Platform environment
An administrator needs to ensure that only users from a specific Microsoft Entra ID group can access a Power Platform environment. What should the administrator configure?
⚠ Common exam trap
It's easy for candidates to confuse access control (security group assignment) with data governance (DLP policies) or capacity management, leading them to select options that address different administrative concerns.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign a security group to the environment in the Power Platform admin center
Assigning a security group to an environment in the Power Platform admin center restricts access to only members of that Microsoft Entra ID group. This is the standard method for controlling user access to a Power Platform environment, ensuring that only authorized users can interact with its resources.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable the 'Create personal productivity environments' setting
Why it's wrong here
Disabling personal productivity environment creation controls whether makers can spin up their own environments; it does not restrict entry to an existing one. It is tempting because it genuinely limits environment sprawl and would be right for governing self-service creation, not for admitting only a specific Microsoft Entra ID group.
- ✓
Assign a security group to the environment in the Power Platform admin center
Why this is correct
Assigning a security group to the environment in the Power Platform admin center restricts access to that group's members, satisfying the requirement that only users from a specific Microsoft Entra ID group can reach the environment. Environment security groups govern who may access an environment, unlike environment roles, which control privileges within it.
- ✗
Set environment capacity limits
Why it's wrong here
Capacity limits govern storage, API request throughput and database allocations, not which identities may enter an environment. It is tempting because capacity planning genuinely constrains how much an environment can consume, and would be the right configuration when an environment is hitting message or storage quotas rather than needing group-based access restriction.
- ✗
Configure a data loss prevention (DLP) policy
Why it's wrong here
DLP policies restrict which connectors and services can exchange data, governing data movement rather than environment sign-in. It is tempting because DLP genuinely enforces governance boundaries and would be correct when preventing business data flowing to consumer connectors, not when limiting environment access to a Microsoft Entra ID group.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.