Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

An organization uses Power Automate flows that connect to Microsoft Dataverse. The flows need to run under a service account with specific permissions. What is the best practice to manage the connection?

⚠ Common exam trap

A common mix-up: candidates confuse 'sharing a flow' with 'changing the runtime identity,' assuming that sharing with a service account grants it execution permissions, when in reality the flow always runs under the connection owner's identity unless a connection reference is used to swap the connection.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Create a connection reference that uses the service account's connection

Connection references decouple the connection details from the flow definition, allowing you to configure a service account's connection once and reuse it across multiple flows. When you create a connection reference and set it to use a service account's connection (e.g., a pre-created Dataverse connection authenticated with the service account), the flow runs under that account's permissions without exposing credentials or requiring the flow owner to share their identity. This is the recommended pattern for service principal or application user scenarios in Power Automate.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use the flow owner's credentials and share the flow with the service account

    Why it's wrong here

    Running under the flow owner's credentials means the service account's Dataverse permissions are never applied, and sharing grants only run-only access, not identity substitution. It tempts because sharing is how makers delegate flows, but that scenario involves personal delegation, not service-account execution.

  • ✓

    Create a connection reference that uses the service account's connection

    Why this is correct

    A connection reference centralises the Dataverse connection so flows reference it rather than embedding credentials, letting the service account's connection be managed and updated in one place. This satisfies the requirement to run flows under a service account with specific permissions.

  • ✗

    Create a service account connection type in the Power Platform admin center

    Why it's wrong here

    The Power Platform admin centre has no service account connection type; connections are created per user identity, so this cannot exist. It tempts administrators wanting centralised credential governance, which is instead achieved by creating the connection while signed in as the service account itself.

  • ✗

    Hardcode the service account credentials in the flow

    Why it's wrong here

    Embedding credentials in the flow definition exposes secrets in plain text to anyone with edit access and breaks when the password rotates. It tempts as a quick way to force a fixed identity, but the correct approach is creating the connection signed in as the service account, so no secret is stored.

About these practice questions

This PL-900 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.