PL-900 Practice Question: Describe the business value of Microsoft Power Platform
An organization wants to enforce that all Power Apps in their tenant use only approved connectors and cannot connect to unmanaged data sources. What should they configure?
⚠ Common exam trap
Many exam-takers confuse DLP policies with Conditional Access or security roles, assuming that access control or user permissions can restrict data source connectivity, when in fact DLP policies are the dedicated mechanism for governing connector usage in Power Platform.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Data Loss Prevention (DLP) policies in the Power Platform admin center
Data Loss Prevention (DLP) policies in the Power Platform admin center are the correct tool to enforce which connectors can be used across Power Apps, Power Automate, and Power Virtual Agents. By classifying connectors as 'Business' or 'Blocked,' administrators can prevent apps from connecting to unmanaged or non-approved data sources, ensuring compliance with organizational data governance requirements.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Conditional Access policies in Microsoft Entra ID
Why it's wrong here
Conditional Access in Microsoft Entra ID controls sign-in conditions such as user, device and location for accessing resources; it cannot restrict which connectors a Power App uses. It would be correct for gating access to Power Platform based on risk or network location, not connector allowlisting.
- ✗
Environment security roles in Dataverse
Why it's wrong here
Dataverse environment security roles govern record-level and table-level data access for users and teams, not which connectors a canvas app may call. They would be the right control for restricting who can read or write specific Dataverse rows, not for tenant-wide connector allowlisting.
- ✓
Data Loss Prevention (DLP) policies in the Power Platform admin center
Why this is correct
DLP policies in the Power Platform admin center classify connectors into Business, Non-Business and Blocked groups, then block combinations across those groups. This directly enforces the tenant-wide constraint that apps use only approved connectors and cannot reach unmanaged data sources.
- ✗
Connector Governance policy in Microsoft Purview
Why it's wrong here
Microsoft Purview connector governance covers data-loss and compliance policies for connectors in Power Platform, not the enforcement of an approved-connector allowlist that blocks unmanaged sources at app design time. It suits auditing and protecting data flows, not restricting which connectors makers can use.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.