Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

An organization wants to allow external partners to access specific Power Apps and data without granting them full access to the tenant. What should they configure?

⚠ Common exam trap

Candidates often confuse sharing the app URL (Option D) with a valid access method, not realizing that Power Apps requires authenticated users with appropriate permissions in the environment, and simply providing a URL does not grant access unless the user is already a guest or member of the tenant.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Invite partners as guest users in Microsoft Entra ID and assign them appropriate security roles in the Power Platform environment.

Inviting external partners as guest users in Microsoft Entra ID (formerly Azure AD) and assigning them appropriate security roles in the Power Platform environment is the standard method for providing controlled, least-privilege access to specific Power Apps and their underlying data sources. This approach leverages Microsoft Entra B2B collaboration to create guest identities, which can then be granted access to specific environments and resources without giving them full tenant-level permissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use Microsoft Intune to manage partner devices.

    Why it's wrong here

    Intune enforces device compliance and configuration; it does not provision external identities or grant them access to Power Apps and data. Intune is tempting because it governs access from unmanaged devices, and it would be correct where the requirement is conditional access based on device compliance state.

  • ✗

    Create a data loss prevention (DLP) policy that allows external sharing.

    Why it's wrong here

    DLP policies restrict which connectors and services can exchange data; they do not grant external identities access to apps or tenant data. DLP is tempting because it governs data movement, and it would be correct when the requirement is preventing sensitive data leaving approved connectors.

  • ✓

    Invite partners as guest users in Microsoft Entra ID and assign them appropriate security roles in the Power Platform environment.

    Why this is correct

    Guest accounts in Microsoft Entra ID grant external partners scoped access without tenant-wide rights, and Power Platform security roles then limit them to the specific apps and data required, satisfying the constraint of no full tenant access.

  • ✗

    Share the app URL with the partners and ask them to sign in with their own accounts.

    Why it's wrong here

    External partners cannot authenticate into the tenant with personal accounts unless they are added as guest users or granted access through an approved external sharing mechanism. Sharing a URL is tempting because internal colleagues open apps this way, but it assumes the recipient already holds valid tenant credentials.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.