PL-900 Practice Question: Manage the Microsoft Power Platform environment
An organization uses Power Apps portals to allow external customers to submit support tickets. The portal uses Microsoft Entra ID for authentication. The security team wants to require multi-factor authentication (MFA) for external portal users. What is the best approach?
⚠ Common exam trap
PL-900 often tests the misconception that MFA can be configured directly inside Power Apps portal settings — in reality, MFA is always enforced by the identity provider via Conditional Access or security defaults.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create a Conditional Access policy in Microsoft Entra ID that requires MFA for the portal application
Conditional Access in Microsoft Entra ID is the supported, centralized mechanism to require MFA for a specific application such as a Power Apps portal. By scoping the policy to the portal enterprise application and setting the grant control to 'Require multi-factor authentication', external users authenticating via Entra ID are challenged for MFA without affecting other apps. This is the recommended approach because portal authentication is delegated to Entra ID, so MFA must be enforced at the identity provider layer.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create a Conditional Access policy in Microsoft Entra ID that requires MFA for the portal application
Why this is correct
A Conditional Access policy in Microsoft Entra ID enforces MFA at the identity provider for the portal application, covering all external users regardless of client. Configuring MFA per-app or per-user would not scale or satisfy the requirement to require MFA for external portal users.
- ✗
Enable MFA for all Microsoft Entra ID users
Why it's wrong here
Blanket MFA for all Microsoft Entra ID users also forces it on internal staff and guests, exceeding the portal-only scope the security team requested. Conditional Access targeting the portal application is the precise control. It tempts because tenant-wide MFA is the quickest toggle, and would suit an organisation mandating MFA for its entire workforce.
- ✗
Use a third-party identity provider that supports MFA
Why it's wrong here
Introducing a third-party identity provider adds federation and migration work while the portal already authenticates against Microsoft Entra ID, which supports MFA natively. It tempts when external users have no Entra ID presence, making a consumer identity store the sensible route; here they already authenticate there.
- ✗
Configure MFA in the Power Apps portal authentication settings
Why it's wrong here
Portal authentication settings govern sign-in behaviour but do not enforce MFA; MFA is controlled by Conditional Access in Microsoft Entra ID. Configuring it here would be right for customising portal sign-in options, yet it cannot satisfy the requirement to challenge external users with a second factor.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.