PL-900 Demonstrate the capabilities of Power Apps Practice Question
An organization is building a model-driven app on Dataverse. They need to ensure that only managers can delete records, and all other users can only edit them. What should be configured?
⚠ Common exam trap
PL-900 often tests the misconception that business rules or flows can enforce security — candidates pick them because they sound like guardrails, but only security roles control record-level privileges.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create custom security roles with different privileges for managers and others
Custom security roles in Dataverse define privileges at the entity level, including Create, Read, Write, Delete, Append, and Append To, with access levels (User, Business Unit, Parent: Child Business Unit, Organization). By creating separate roles for managers and other users, you can grant Delete only to managers while giving others Write access. This is the native, supported way to enforce record-level permissions.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Add a business rule that checks user role before delete
Why it's wrong here
Business rules run client-side on form events and cannot evaluate security roles for delete operations; they also do not fire on deletes performed outside the form. Tempting because business rules commonly enforce field-level logic, and would suit validation or field visibility, but record deletion is controlled by Dataverse security roles with Delete privilege.
- ✗
Implement a Power Automate flow that cancels delete
Why it's wrong here
A Power Automate flow triggers after the delete request is processed, so it cannot prevent the deletion; cancellation requires a pre-operation plug-in. Tempting because flows automate Dataverse events, and would be correct for notifications or downstream updates, but privilege enforcement belongs to Dataverse security roles.
- ✗
Use a business process flow to restrict delete
Why it's wrong here
Business process flows guide users through stages of a defined process and cannot grant or deny delete privileges. Tempting because they shape record progression in model-driven apps, and would be correct for enforcing a structured sequence of stages, but delete permission is set by Dataverse security roles, not process design.
- ✓
Create custom security roles with different privileges for managers and others
Why this is correct
Security roles define privilege levels per entity, including Delete versus Write, and can be assigned to teams or users. Managers receive a role granting Delete; others receive a role with Write but no Delete, precisely satisfying the stated constraint.
Go deeper
Related to this question
About these practice questions
This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.