PL-900 Practice Question: Manage the Microsoft Power Platform environment
An organization wants to ensure that when a Power Apps canvas app is shared with a user, the user can run the app but cannot edit it or share it with others. The app is in a production environment. What should the administrator or maker do?
⚠ Common exam trap
It's easy for candidates to confuse data source security roles or solution types with app sharing permissions; only the 'Can use' permission restricts a user to running the app without editing or sharing.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Share the app with the user and assign the 'Can use' permission only.
Canvas app sharing permissions are managed directly when sharing the app. The 'Can use' permission allows users to run the app but not edit or reshare it. 'Can edit' grants modification rights. Security roles and solution packaging do not control app-level sharing permissions, so they are not the correct mechanisms for this requirement.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Publish the app as a managed solution and assign the user the 'System Customizer' role.
Why it's wrong here
Publishing as a managed solution affects how the app is transported between environments, not how it is shared with end users. The 'System Customizer' role grants broad customization privileges, which would allow editing and potentially sharing. This does not meet the requirement to restrict the user to running the app only.
- ✗
Add the user to a security role that has only read access to the app's data source.
Why it's wrong here
Data source security roles control access to data, not the ability to edit or share the app itself. Even with read-only data access, the user could still edit the app if granted 'Can edit' permission. This approach does not address the app sharing permissions required.
- ✓
Share the app with the user and assign the 'Can use' permission only.
Why this is correct
When sharing a canvas app, you can assign either 'Can use' or 'Can edit' permissions. 'Can use' allows the user to run the app but not modify it or share it. This directly meets the requirement to restrict the user to running the app only, without editing or sharing capabilities.
- ✗
Share the app with the user and assign the 'Can edit' permission, then remove the user's Environment Maker role.
Why it's wrong here
The 'Can edit' permission allows the user to modify the app. Removing the Environment Maker role does not prevent editing if the user has been granted 'Can edit' on the app itself. This combination still grants editing rights, which violates the requirement.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.