PL-900 Practice Question: Manage the Microsoft Power Platform environment
An organization has multiple Power Platform environments. The security team mandates that all environments must use Microsoft Entra ID conditional access policies to enforce multi-factor authentication. However, one environment hosts a service account that cannot perform interactive logins. What should the administrator do to comply without breaking the service account?
⚠ Common exam trap
The trap is thinking MFA can be configured 'inside' a Power Platform environment or that isolating the service account in a new environment bypasses tenant-level Conditional Access — CA is enforced at the Entra ID identity layer and applies tenant-wide.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Exclude the service account from the conditional access policy
Conditional Access policies in Microsoft Entra ID support targeted exclusions for specific users, groups, or service principals. Excluding the non-interactive service account from the MFA-requiring policy allows it to authenticate programmatically (e.g., via client credentials or service principal) without triggering an interactive MFA challenge, while all other users remain protected. This is the standard, supported approach for service accounts that cannot perform interactive logins.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Create a new environment for the service account
Why it's wrong here
Moving the service account to a new environment does not remove the conditional access requirement, since the mandate applies to all environments. It tempts administrators seeking isolation, but the actual fix is scoping a conditional access policy to exclude the non-interactive workload identity, which works regardless of environment.
- ✗
Change the service account to use interactive login
Why it's wrong here
Service accounts are non-interactive by design; forcing interactive sign-in breaks automation and still cannot satisfy MFA prompts reliably. It appeals because MFA is normally satisfied interactively, but the requirement is to exempt the workload identity via a conditional access exclusion rather than alter how the account authenticates.
- ✓
Exclude the service account from the conditional access policy
Why this is correct
Conditional access applies only to interactive sign-ins, so a non-interactive service account cannot satisfy MFA prompts. Excluding it from the policy preserves the account's workload authentication while the remaining environments stay compliant with the security team's mandate.
- ✗
Disable MFA for that environment
Why it's wrong here
Disabling MFA abandons the conditional access mandate entirely, leaving the environment non-compliant and the service account unprotected. It is tempting because service accounts cannot complete interactive prompts, but the correct approach is a conditional access policy scoped to exclude that workload identity, not to switch MFA off environment-wide.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.