Courseiva

CCNA Manage the Microsoft Power Platform environment Questions

75 of 95 questions · Page 1/2 · Manage the Microsoft Power Platform environment · Answers revealed

1
MCQhard

An administrator needs to prevent users from creating Power Apps outside of the approved environment (Production). The company has a Development and a Production environment. Users should only be able to create apps in Development. Which configuration should the administrator use?

A.Assign the Environment Maker role to users in both environments
B.Assign the Environment Maker role to users only in the Development environment
C.Create a DLP policy that blocks app creation in Production
D.Remove the Environment Maker role from all users in all environments
AnswerB

Environment Maker permits app creation within a given environment. Granting it only in Development means users can build there, while lacking the role in Production prevents them from creating apps in that environment, satisfying the restriction.

Why this answer

The Environment Maker role grants permission to create apps within a specific environment. By assigning this role only to the Development environment, users can create apps there but are blocked from creating them in Production, where they lack the role. This directly enforces the requirement without affecting other permissions.

Exam trap

The trap here is that candidates often confuse DLP policies with environment-level permissions, incorrectly assuming DLP can block app creation, when in fact DLP only restricts data connectors and sharing, not the ability to create apps.

How to eliminate wrong answers

Option A is wrong because assigning the Environment Maker role to users in both environments would allow app creation in Production, violating the requirement. Option C is wrong because Data Loss Prevention (DLP) policies control data connectors and sharing, not the ability to create apps; they cannot block app creation itself. Option D is wrong because removing the Environment Maker role from all users in all environments would prevent app creation in Development as well, failing to meet the requirement that users should be able to create apps in Development.

2
MCQhard

Northwind Traders has a production environment named 'Ops-Prod' with Dataverse enabled. A maker reports that after importing a managed solution, a canvas app that previously worked now fails to connect to a custom connector. The admin confirms the connector exists in the environment and the maker holds the Environment Maker role. What is the most likely cause?

A.Managed solutions block all outbound calls from custom connectors until a data loss prevention policy is relaxed.
B.The maker requires the System Administrator role to use any custom connector in a managed solution.
C.The custom connector must be promoted to a certified connector before it can be used inside a canvas app.
D.The custom connector's connection was not re-established by the maker after the solution import, so the app references a missing or unauthorized connection.
AnswerD

Connections are user-specific artifacts and are not carried inside a solution. After importing a managed solution that includes a custom connector, each user must create their own connection to that connector, and the app must reference a connection the running user owns. Because the maker holds Environment Maker but no connection existed yet, the app fails at runtime, matching the symptom precisely.

Why this answer

Solution import brings across component definitions such as the custom connector, but never the user-specific connection objects. Each maker must create their own connection to the connector after import, and the app must reference a connection the user owns. Because the connector existed and the maker had Environment Maker rights, the missing or unauthorized connection is the most plausible cause of the runtime failure.

Exam trap

The trap here is assuming that a solution carries connections along with the connector, when connections are per-user artifacts that must be recreated after import.

3
MCQhard

A global company uses Power Platform and wants to ensure that data residency requirements are met for users in different regions. What should they configure?

A.In the Power Platform admin center, create environments in the appropriate geographic regions (e.g., Europe, United States).
B.Create data loss prevention (DLP) policies to block data movement between regions.
C.Configure Microsoft Entra ID Conditional Access policies to restrict access based on geographic location.
D.Use Microsoft Purview to tag environments with data residency labels.
AnswerA

Environments are the isolation boundary in Power Platform, and each is created in a specific geographic region where its data is stored. Creating environments in the required regions satisfies the stem's data residency constraint, since region selection at environment creation determines where data resides.

Why this answer

Power Platform environments are the boundary for data storage and compute. By creating environments in specific geographic regions (e.g., Europe, United States) via the Power Platform admin center, the company ensures that all data for that environment resides in the chosen region, meeting data residency requirements. This is the primary mechanism for controlling data location in Power Platform.

Exam trap

The trap here is that candidates confuse data residency (where data is stored) with data protection policies (DLP) or access control (Conditional Access), leading them to select options that manage data movement or access rather than storage location.

How to eliminate wrong answers

Option B is wrong because data loss prevention (DLP) policies control data movement between connectors and services, not the geographic storage location of data; they cannot enforce data residency. Option C is wrong because Microsoft Entra ID Conditional Access policies control user authentication and access based on location, but they do not affect where data is stored or processed. Option D is wrong because Microsoft Purview is used for data governance, classification, and compliance, but it does not have the capability to tag environments with data residency labels or control data storage location.

4
MCQhard

Refer to the exhibit. A Power Platform administrator applies this DLP policy to the default environment. What is the result?

A.All connectors are allowed
B.All connectors are blocked
C.The policy applies to all environments
D.Microsoft Teams and Twitter connectors are blocked in the default environment
AnswerD

Connectors assigned to the Blocked group in a data loss prevention policy are disabled for every app and flow in the environment where the policy applies. With Microsoft Teams and Twitter placed there, the default environment loses access to both connectors.

Why this answer

The exhibit shows a Data Loss Prevention (DLP) policy configured with Microsoft Teams and Twitter connectors in the 'Blocked' group. Since this policy is applied to the default environment, only those two connectors are blocked in that environment. All other connectors remain in the 'Allowed' group by default, so they are permitted.

Therefore, the correct result is that Microsoft Teams and Twitter connectors are blocked in the default environment.

Exam trap

The trap here is that candidates may assume a DLP policy blocks all connectors or applies globally, when in fact only the connectors explicitly placed in the 'Blocked' group are restricted, and the policy scope is limited to the specified environment.

How to eliminate wrong answers

Option A is wrong because not all connectors are allowed; the policy explicitly blocks Microsoft Teams and Twitter connectors. Option B is wrong because only the two blocked connectors are prohibited, not all connectors. Option C is wrong because the policy is scoped to the default environment only, not to all environments; DLP policies can be applied to specific environments or the entire tenant, but the question states it is applied to the default environment.

5
MCQhard

A Power Platform administrator is configuring data loss prevention (DLP) policies for a tenant. The administrator needs to allow the use of the SharePoint connector and the Outlook connector in the same flow, but must block the use of the Twitter connector. Which DLP policy configuration should the administrator use?

A.Add SharePoint to the Business data group, add Outlook to the Non-Business data group, and add Twitter to the Blocked group.
B.Add SharePoint and Outlook to the Non-Business data group, and add Twitter to the Business data group.
C.Add SharePoint and Outlook to the Blocked group, and add Twitter to the Non-Business data group.
D.Add SharePoint and Outlook to the Business data group, and add Twitter to the Blocked group.
AnswerD

DLP policies group connectors into Business, Non-Business, and Blocked. Connectors in the Business group can be used together. Twitter in the Blocked group cannot be used at all. This configuration allows SharePoint and Outlook in the same flow while blocking Twitter, exactly as required.

Why this answer

DLP policies classify connectors into Business, Non-Business, and Blocked groups. Connectors in the same group can be used together in a flow. To allow SharePoint and Outlook together, they must be in the same group, such as Business.

To block Twitter, it must be placed in the Blocked group. This configuration satisfies both conditions.

Exam trap

The trap here is assuming that connectors in different groups can still be combined, but DLP policies prevent cross-group usage.

6
MCQhard

A company uses a Power Platform environment that contains several production apps. They need to ensure that changes to these apps are reviewed and approved before deployment to the production environment. What should they implement?

A.Create data loss prevention (DLP) policies for the production environment.
B.Use managed solutions and Azure DevOps for application lifecycle management (ALM) with deployment gates.
C.Assign the System Administrator role to all developers.
D.Configure Microsoft Purview to audit changes and require approval.
AnswerB

Managed solutions are immutable in the target environment, so production changes cannot be edited directly. Pairing them with Azure DevOps pipelines enforces deployment gates, requiring review and approval before release. This satisfies the requirement that changes be approved prior to production deployment.

Why this answer

Managed solutions and Azure DevOps with deployment gates provide a structured Application Lifecycle Management (ALM) process. This allows changes to be reviewed, tested, and approved before deployment to a production environment, ensuring governance and control over modifications.

Exam trap

The trap here is that candidates may confuse data governance (DLP) or auditing (Purview) with the deployment approval process, or mistakenly think that granting admin rights to all developers is a valid way to manage changes, rather than recognizing the need for a formal ALM pipeline with approval gates.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies control data flow between connectors and environments, not the review and approval of app changes. Option C is wrong because assigning the System Administrator role to all developers grants excessive permissions, bypassing the need for review and approval, and violates the principle of least privilege. Option D is wrong because Microsoft Purview is a compliance and auditing tool, not a mechanism for enforcing approval workflows on app deployments.

7
MCQeasy

A Power Platform administrator needs to provide a team of makers with a shared environment that includes preinstalled sample data and apps for learning purposes. The team should be able to reset the environment to its initial state if needed. Which environment type should the administrator create?

A.Production
B.Default
C.Developer
D.Sandbox
AnswerD

Sandbox environments are designed for development, testing, and training. They can include sample data and apps, and administrators can reset them to a clean state. This matches the requirement for a shared learning environment that can be reset.

Why this answer

Sandbox environments are the correct choice for training and testing because they support sample data and apps, and can be reset to a clean state. They are shared environments that can be assigned to a security group, making them ideal for a team of makers learning Power Platform.

Exam trap

The trap here is confusing Developer environments with team training environments, but Developer environments are single-user and cannot be reset.

8
MCQeasy

A company wants to ensure that changes to a Power Platform solution are tracked and can be rolled back if necessary. The development team uses source control. What should the administrator configure to enable solution lifecycle management?

A.Use managed solutions and export to source control
B.Backup the environment daily
C.Share the app with the team
D.Disable sharing to prevent changes
AnswerA

Managed solutions are locked, so changes are made only in a development environment and shipped as versioned artefacts. Exporting them to source control gives traceable history and enables rollback to a prior solution version, meeting the lifecycle management requirement.

Why this answer

Solution lifecycle management in Power Platform relies on the ALM pattern: develop in an unmanaged solution, export it as a managed solution, and store the solution source (including the .zip and unpacked XML) in a source control repository such as Azure DevOps or GitHub. Managed solutions are immutable in target environments, preventing out-of-band edits, and the source-controlled artifacts enable versioning, diffing, and rollback by re-importing a prior version.

Exam trap

PL-900 often tests the confusion between backup (data recovery) and source control (solution versioning), leading candidates to pick 'backup the environment' as if it enabled rollback of solution changes.

How to eliminate wrong answers

Option B is wrong because daily environment backups protect against data loss and disaster recovery, not solution version tracking or rollback of configuration changes. Option C is wrong because sharing an app grants end-user access and has nothing to do with source control or lifecycle management. Option D is wrong because disabling sharing prevents users from running the app but does not track changes or enable rollback.

9
MCQmedium

A Power Platform administrator notices that a production environment has exceeded its storage quota. The administrator needs to free up storage without impacting active solutions. Which action should the administrator take first?

A.Analyze storage by entity and delete unused custom tables
B.Increase the storage quota
C.Remove the environment and create a new one
D.Delete all audit logs older than 30 days
AnswerA

Analysing storage by entity identifies which custom tables consume the most capacity, letting the administrator delete genuinely unused ones. This frees quota directly without altering or removing components that active solutions depend on, satisfying the no-impact constraint.

Why this answer

Analyzing storage by entity allows the administrator to identify which custom tables consume the most space, and deleting unused custom tables directly frees up storage without affecting active solutions. This is the recommended first step in the Power Platform admin center, as it targets the root cause of storage overage while preserving production functionality.

Exam trap

The trap here is that candidates may assume deleting audit logs is the quickest fix, but the question emphasizes 'without impacting active solutions,' and audit logs are often not the largest storage consumer, making analysis of custom tables the correct first step.

How to eliminate wrong answers

Option B is wrong because increasing the storage quota does not free up existing storage; it only adds capacity, which may incur additional costs and does not resolve the underlying issue of excessive data consumption. Option C is wrong because removing the environment and creating a new one would destroy all solutions, data, and configurations, severely impacting active solutions and causing data loss. Option D is wrong because deleting audit logs older than 30 days may free some storage, but audit logs are typically a small fraction of total storage; this action is not the first step and may not address the primary storage consumer, which is often custom table data.

10
MCQeasy

A help desk technician needs to confirm which Power Platform environments are associated with a specific Microsoft Dataverse database and check the environment type and region for each. The technician has the Power Platform Administrator role. Where should the technician look?

A.The Environments list in the Power Platform admin center, opening the environment details pane
B.The Microsoft 365 admin center, Active users blade
C.The Capacity page in the Power Platform admin center
D.The Default environment's Solutions list in make.powerapps.com
AnswerA

The Environments page in the Power Platform admin center lists every environment with its type, region, and whether a Dataverse database is present. Opening an environment's details shows the database configuration and environment metadata, which is exactly what the technician needs to verify.

Why this answer

The Environments page in the Power Platform admin center is the authoritative inventory: it lists each environment with type, region, and database status, and the details pane exposes database configuration. A Power Platform Administrator can open it directly, making it the correct place to confirm which environments have Dataverse and to read environment metadata.

Exam trap

The trap here is confusing the Capacity page with the Environments page, since both are in the admin center but only one lists environment metadata.

11
MCQmedium

A Power Platform administrator is setting up a new environment for a department. The department requires that data stored in the environment remain within a specific geographic region. The administrator creates the environment in the Europe region. Which additional step must the administrator take to ensure that all data, including backups, stays in that region?

A.Create a data loss prevention policy that blocks connectors outside the region.
B.Configure the environment's region during creation; no further action is required.
C.Enable the 'Data residency' setting in the Power Platform admin center.
D.Assign the environment to a security group that is restricted to users in that region.
AnswerB

When you create an environment in the Power Platform admin center, you select a region, and all data, including backups, is stored within that region's data centers. No additional setting is needed to enforce data residency. The region selection at creation is the definitive control, so the administrator's action of creating it in Europe already satisfies the requirement.

Why this answer

Data residency in Power Platform is determined by the region chosen when an environment is created. The environment's data, including backups, is stored in data centers within that region. No additional configuration is required to enforce this.

The administrator's creation of the environment in the Europe region already ensures that data remains in that geography, making other proposed steps unnecessary or ineffective.

Exam trap

The trap here is assuming that data residency requires a separate toggle or policy, when it is actually established solely by the environment's region at creation.

12
MCQeasy

A Power Platform administrator wants to delegate the responsibility of managing environments to regional leads without granting them full admin privileges. Which role should the administrator assign?

A.Environment Admin role.
B.Dynamics 365 Administrator role.
C.System Customizer role.
D.Power Platform Administrator role.
AnswerA

The Environment Admin role grants administrative rights scoped to specific environments, letting regional leads manage those environments without tenant-wide privileges. This directly satisfies the stem's constraint of delegating environment management while withholding full administrator access.

Why this answer

The Environment Admin role grants administrative rights scoped to a specific environment, allowing the user to manage that environment's settings, users, and resources without full tenant-wide admin privileges. This is the correct role for delegating environment management to regional leads.

Exam trap

PL-900 often tests the confusion between tenant-wide admin roles (Power Platform Administrator) and environment-scoped roles (Environment Admin), causing candidates to over-grant privileges.

How to eliminate wrong answers

Option B is wrong because the Dynamics 365 Administrator role is a tenant-level role tied to Dynamics 365 services, not a scoped environment delegation role. Option C is wrong because System Customizer is a Dataverse security role that allows customization of tables and forms within an environment, not administrative management of the environment itself. Option D is wrong because Power Platform Administrator is a tenant-wide role that grants full administrative rights across all environments, which exceeds the least-privilege requirement.

13
MCQeasy

A company has a Power Platform environment that contains several unmanaged solutions. The administrator wants to promote a solution to production. Which action should the administrator take to ensure the solution can be deployed to other environments?

A.Export the solution as a managed solution
B.Use the 'Backup' feature in the admin center
C.Apply a solution patch and export it
D.Clone the solution and export as unmanaged
AnswerA

Exporting as managed strips the unmanaged customisation layer and locks the solution, so it can be imported cleanly into production and other environments. This satisfies the deployment requirement, since unmanaged solutions are intended only for development and cannot be reliably promoted.

Why this answer

Exporting a solution as a managed solution is the correct action because managed solutions are designed for deployment to production and other non-development environments. They prevent direct customization of components, enforce solution layering, and allow for proper lifecycle management, including upgrades and patching. Unmanaged solutions, by contrast, are intended for development and cannot be reliably deployed to production without breaking the component ownership model.

Exam trap

The trap here is that candidates confuse the 'Backup' feature with solution deployment, or assume that exporting as unmanaged is acceptable for production because it preserves all components, but they overlook the critical requirement for managed solutions to enforce lifecycle control and prevent direct customization.

How to eliminate wrong answers

Option B is wrong because the 'Backup' feature in the admin center creates a full environment backup, not a portable solution package; it cannot be selectively deployed to another environment and does not support solution lifecycle management. Option C is wrong because applying a solution patch and exporting it creates a patch that depends on the parent managed solution; patches are intended for minor updates to an already-deployed managed solution, not for initial deployment to production. Option D is wrong because cloning a solution and exporting it as unmanaged preserves the unmanaged state, which allows direct customization in the target environment, breaking the managed solution deployment model and causing future upgrade conflicts.

14
MCQeasy

A company is implementing Microsoft Power Platform and needs to ensure that only licensed users can create environments. Which setting should be enabled?

A.Enable 'Create database' in the tenant settings
B.Enable 'Create solutions' in the Power Platform admin center
C.Enable 'Create environments' in the Power Platform admin center tenant settings
D.Enable 'Create apps' in the Power Platform admin center
AnswerC

This setting controls whether users can create environments.

Why this answer

The 'Create environments' setting in the Power Platform admin center tenant settings is the specific control that restricts environment creation to licensed users only. By default, this setting is enabled for all users, but administrators can disable it to limit creation to users with a Power Platform license (e.g., Power Apps per user plan, Power Automate per user plan, or Dynamics 365 licenses). This ensures compliance with licensing requirements and prevents unlicensed users from consuming capacity.

Exam trap

The trap here is that candidates confuse environment-level permissions (like 'Create database' or 'Create apps') with the tenant-level setting that controls environment creation, leading them to select a granular permission that does not address the licensing requirement.

How to eliminate wrong answers

Option A is wrong because 'Create database' is a setting within a specific environment (not tenant-wide) that controls whether users can add a Dataverse database to an existing environment; it does not govern who can create new environments. Option B is wrong because 'Create solutions' is a permission related to building and managing solutions within an environment, not a tenant-level setting for environment creation. Option D is wrong because 'Create apps' is a permission that controls the ability to create canvas or model-driven apps within an environment, not the ability to provision new environments.

15
MCQhard

An organization has multiple Power Platform environments. The administrator needs to move a solution from a development environment to a production environment. The solution includes custom connectors and environment variables. What is the correct process?

A.Copy the entire development environment to production
B.Export an unmanaged solution from development and import it into production
C.Manually re-create all components in production
D.Export a managed solution from development and import it into production
AnswerD

Managed solutions are the supported transport for moving components such as custom connectors and environment variables between environments, since they cannot be modified in the target and preserve the solution's configuration. Exporting from development and importing into production satisfies the stated requirement.

Why this answer

Managed solutions are the standard mechanism for deploying customizations (including custom connectors and environment variables) from a development environment to a production environment. Exporting a managed solution from development and importing it into production ensures that components are packaged as a single, deployable unit, and it prevents accidental modifications in production by making the solution layers read-only after import.

Exam trap

The trap here is that candidates often confuse unmanaged and managed solutions, mistakenly thinking that exporting an unmanaged solution (Option B) is acceptable for production deployment, when in fact only managed solutions enforce the intended lifecycle and prevent unauthorized edits in production.

How to eliminate wrong answers

Option A is wrong because copying the entire development environment to production would overwrite production data and configurations, and it is not a supported method for solution deployment—Power Platform does not allow direct environment cloning for production use. Option B is wrong because exporting an unmanaged solution from development and importing it into production would leave all components editable in production, which violates change management best practices and can lead to configuration drift; unmanaged solutions are intended for development work, not production deployment. Option C is wrong because manually re-creating all components in production is error-prone, time-consuming, and defeats the purpose of using solutions for lifecycle management; it also introduces a high risk of inconsistencies between environments.

16
MCQmedium

A company uses Power BI to visualize sales data from Dynamics 365 Sales. A new policy requires that all data must be stored in the US region only. The Power BI tenant is currently in the default region (home region). What should the admin do to comply with the policy?

A.Change the Microsoft Entra ID location to US
B.Apply a data classification label to restrict storage
C.Set the workspace region to US in Power BI settings
D.Provision Power BI Premium capacity in the US region
AnswerD

Premium capacity can be assigned to a specific region, enforcing data residency.

Why this answer

Provisioning Power BI Premium capacity in the US region and assigning workspaces to that capacity enforces data residency in the US. Option A is incorrect because Microsoft Entra ID location does not control Power BI data storage. Option B is incorrect because data classification labels do not enforce physical data location.

Option C is incorrect because setting the workspace region is only available with Premium capacity, but without Premium capacity, the workspace region defaults to the tenant home region and cannot be changed.

17
MCQmedium

A company uses Power Automate flows that connect to SharePoint and Microsoft Entra ID. The administrator needs to ensure that the flows can access data only from approved data sources. What should the administrator configure?

A.Define SharePoint site permissions for the flows
B.Create a Data Loss Prevention (DLP) policy that restricts connectors to approved data sources
C.Configure data policies in Power Apps settings
D.Set connector sharing permissions to limit access
AnswerB

A Data Loss Prevention policy in Power Platform classifies connectors into business, non-business and blocked groups, preventing flows from combining approved and unapproved data sources. This enforces the restriction to approved sources across SharePoint and Microsoft Entra ID connectors.

Why this answer

Data Loss Prevention (DLP) policies in the Power Platform allow administrators to control which connectors can be used together in flows and apps, effectively restricting flows to approved data sources like SharePoint and Microsoft Entra ID. By classifying connectors as Business or Non-Business, DLP policies prevent unauthorized data sharing between environments, which directly addresses the requirement to limit data access to approved sources.

Exam trap

The trap here is that candidates often confuse DLP policies with SharePoint permissions or connector sharing, thinking that restricting user access to SharePoint sites is sufficient to control flow data sources, when in fact DLP policies are the only mechanism that can restrict which connectors a flow can use at the environment level.

How to eliminate wrong answers

Option A is wrong because SharePoint site permissions control user access to SharePoint content, not the data sources that Power Automate flows can connect to; flows run under their own service principal or user context and are not governed by site-level permissions alone. Option C is wrong because data policies in Power Apps settings are a legacy concept that has been replaced by the unified DLP policy management in the Power Platform admin center, and they do not provide the granular connector-level restriction needed for flows. Option D is wrong because connector sharing permissions control which users or groups can use a specific connector instance, not which data sources (connectors) are allowed or blocked across the entire environment.

18
Multi-Selecteasy

Which TWO are valid ways to distribute a Power App to end users? (Select 2)

Select 2 answers
A.Add the app to Microsoft Teams
B.Email the app as an attachment
C.Share the app directly with users or groups
D.Export the app and send it as a .msapp file
E.Publish the app to Microsoft AppSource
AnswersA, C

Apps can be added to Teams for easy access.

Why this answer

Power Apps can be added directly to Microsoft Teams as a tab or personal app, allowing end users to access the app within the Teams interface without leaving the collaboration environment. This leverages the Teams integration capabilities of Power Apps, which uses the Teams manifest and the Power Apps app for Teams to provide seamless access.

Exam trap

The trap here is that candidates often confuse exporting a .msapp file (a developer artifact) with a distribution method, or think emailing an app as an attachment is possible, when in reality Power Apps must be shared through the platform's sharing mechanism or embedded in a supported host like Teams or SharePoint.

19
MCQeasy

A university uses Power Apps for student registration. The app is built on Dataverse and shared with all students. Recently, a student reported that they cannot access the app and receive an error that they do not have permission. The app was working earlier. The admin checks the environment and finds that the app's sharing settings have been changed. The admin needs to restore access for all students quickly. What should the admin do?

A.Contact Microsoft Support to restore the previous sharing settings.
B.Assign the 'Environment Maker' role to all students.
C.Re-create the app from a backup.
D.Share the app with the 'All Students' security group in the Power Apps maker portal.
AnswerD

Re-sharing the app with the 'All Students' security group in the Power Apps maker portal restores access for every member at once. Group-based sharing is the quickest route, since the changed sharing settings removed the students' permissions.

Why this answer

Sharing the app with the 'All Students' security group in the Power Apps maker portal restores access for all students quickly and correctly. Security groups are the recommended way to manage access at scale in Dataverse-backed apps.

Exam trap

PL-900 often tests whether candidates choose overly complex or inappropriate fixes (support tickets, role escalation, app recreation) when the correct action is simply re-sharing the app with the appropriate security group.

How to eliminate wrong answers

Option A is wrong because contacting Microsoft Support is slow and unnecessary when the admin can restore sharing directly. Option B is wrong because assigning the Environment Maker role grants broad privileges beyond app access and is not appropriate for students. Option C is wrong because re-creating the app from backup is disruptive and does not address the sharing permission issue.

20
Multi-Selecthard

A company is migrating a complex Power Apps solution from a development environment to production. The solution includes custom connectors, flows, and Dataverse tables. Which THREE steps should the administrator take to ensure a successful migration?

Select 3 answers
A.Test the solution in a staging environment first
B.Delete the development environment after export
C.Export the solution as a managed solution
D.Manually recreate the solution in production
E.Run the solution checker to identify issues
AnswersA, C, E

Deploying to a staging environment first exercises the solution's custom connectors, flows and Dataverse tables against a production-like target, exposing environment-specific connection references or configuration gaps before the production import, satisfying the migration's need to verify behaviour safely.

Why this answer

To ensure a successful migration, the administrator should test the solution in a staging environment first (A) to validate functionality, export it as a managed solution (C) to maintain component relationships and support future upgrades, and run the solution checker (E) to identify and fix issues before migration. Deleting the development environment after export (B) is risky because it removes the source before the migration is verified. Manually recreating the solution in production (D) is error-prone and not recommended.

21
MCQeasy

A manufacturing company uses Power Automate flows to process inventory updates. The flows use standard connectors. The company needs to ensure that the flows can be run by users in their own context without requiring the flow owner's credentials. Which authentication type should be used for the connections?

A.Owner-provided credentials
B.User-provided credentials
C.Anonymous authentication
D.Service principal authentication
AnswerB

User-provided credentials embed each user's own sign-in within the connection, so flows run in that user's context rather than the owner's. This satisfies the stem's requirement that users run flows without the flow owner's credentials.

Why this answer

User-provided credentials (option B) are correct because they allow each user who runs the flow to authenticate with their own identity, enabling the flow to execute in the user's context without requiring the flow owner's credentials. This is essential when flows are shared with multiple users and need to respect individual permissions and data access.

Exam trap

The trap here is that candidates often confuse 'owner-provided credentials' with the default behavior of shared flows, not realizing that user-provided credentials are required to run flows in each user's own context rather than the owner's context.

How to eliminate wrong answers

Option A is wrong because owner-provided credentials would force all users to run the flow under the flow owner's identity, which violates the requirement that users run flows in their own context and introduces security risks. Option C is wrong because anonymous authentication is not supported for standard connectors in Power Automate; all connectors require some form of authenticated identity. Option D is wrong because service principal authentication is used for server-to-server or automated scenarios, not for flows triggered or run by individual users in their own context.

22
Multi-Selectmedium

A Power Platform administrator needs to manage user access to a specific environment. The administrator wants to allow a group of users to create apps and flows in that environment, but restrict them from modifying environment settings or managing other users. Which two actions should the administrator perform? (Choose two.)

Select 2 answers
A.Assign the Environment Admin role to the group of users for the environment.
B.Add the users to the environment's Maker security group (if using security groups).
C.Assign the Environment Maker role to the group of users for the environment.
D.Assign the Power Platform Administrator role to the group of users.
E.Ensure the users have the Common Data Service User security role in the environment.
AnswersB, C

If the environment is configured to use security groups, adding users to the Maker security group grants them the Environment Maker role, enabling them to create apps and flows. This is a valid method to assign the appropriate permissions without granting administrative rights.

Why this answer

To allow users to create apps and flows without granting administrative rights, the administrator should assign the Environment Maker role. This can be done directly or by adding users to the environment's Maker security group if security groups are used. These actions provide the necessary creation permissions while adhering to least privilege, unlike Environment Admin or tenant-level roles.

Exam trap

The trap here is confusing the Environment Maker role with the Environment Admin role; the Maker role allows creation but not management, which is exactly what is needed.

23
MCQmedium

An organization uses Power Automate flows that connect to Microsoft Dataverse. The flows need to run under a service account with specific permissions. What is the best practice to manage the connection?

A.Use the flow owner's credentials and share the flow with the service account
B.Create a connection reference that uses the service account's connection
C.Create a service account connection type in the Power Platform admin center
D.Hardcode the service account credentials in the flow
AnswerB

A connection reference centralises the Dataverse connection so flows reference it rather than embedding credentials, letting the service account's connection be managed and updated in one place. This satisfies the requirement to run flows under a service account with specific permissions.

Why this answer

Connection references decouple the connection details from the flow definition, allowing you to configure a service account's connection once and reuse it across multiple flows. When you create a connection reference and set it to use a service account's connection (e.g., a pre-created Dataverse connection authenticated with the service account), the flow runs under that account's permissions without exposing credentials or requiring the flow owner to share their identity. This is the recommended pattern for service principal or application user scenarios in Power Automate.

Exam trap

The trap here is that candidates confuse 'sharing a flow' with 'changing the runtime identity,' assuming that sharing with a service account grants it execution permissions, when in reality the flow always runs under the connection owner's identity unless a connection reference is used to swap the connection.

How to eliminate wrong answers

Option A is wrong because sharing a flow with a service account does not change the runtime identity; the flow still executes under the original owner's credentials, not the service account's permissions. Option C is wrong because there is no 'service account connection type' in the Power Platform admin center; connection types are defined by connectors, not created in the admin center. Option D is wrong because hardcoding credentials violates security best practices, exposes secrets in plaintext, and breaks when passwords rotate or policies change.

24
Multi-Selectmedium

An administrator is planning the environment strategy for a large enterprise. Which TWO considerations should the administrator include to ensure proper governance?

Select 2 answers
A.Use only the default environment to simplify management
B.Establish environment naming conventions
C.Disable environment monitoring to reduce overhead
D.Implement data loss prevention (DLP) policies
E.Allow all connectors to maximize flexibility
AnswersB, D

Consistent environment naming conventions let administrators identify each environment's purpose, owner and lifecycle at a glance, which is essential for governance across a large tenant. They also underpin auditing, access reviews and policy assignment, satisfying the stem's requirement for scalable oversight rather than ad hoc management.

Why this answer

Environment naming conventions and DLP policies are key governance considerations. Option B (establish naming conventions) helps organize environments; Option D (implement DLP policies) protects data. Option A is wrong because using only the default environment is not recommended for governance.

Option C is wrong because disabling environment monitoring reduces visibility and control. Option E is wrong because allowing all connectors poses a security risk.

25
Multi-Selectmedium

Which THREE are valid components of a Microsoft Power Platform environment?

Select 3 answers
A.Custom connector
B.Dataverse database
C.Power BI workspace
D.Microsoft 365 Group
E.Power Automate flow
AnswersA, B, E

Custom connectors are stored in environments.

Why this answer

A custom connector is a valid component of a Microsoft Power Platform environment because it allows you to extend the platform by creating your own API connectors to external services. Custom connectors are stored and managed within an environment, enabling makers to build apps and flows that interact with systems not covered by out-of-the-box connectors.

Exam trap

The trap here is that candidates confuse shared Microsoft 365 resources (like Groups or Power BI workspaces) with Power Platform environment components, but only items directly managed within the environment's scope—such as custom connectors, Dataverse databases, and Power Automate flows—are valid components.

26
MCQmedium

A company wants to restrict the ability to create Power Apps and Power Automate flows in the default environment to only a specific security group. What is the recommended approach?

A.Create a DLP policy that blocks creation of apps and flows.
B.Assign the security group to the Environment Maker role for the default environment.
C.Disable the default environment and create a new one with restricted access.
D.Remove the Environment Maker role from all users and add the security group as co-admins.
AnswerB

The Environment Maker role can be scoped to a specific environment and assigned to a security group.

Why this answer

The recommended approach to restrict app and flow creation in the default environment is to assign only the desired security group to the Environment Maker role for that environment. The Environment Maker role grants permissions to create resources like Power Apps and Power Automate flows, and by assigning it exclusively to a security group, you effectively limit creation capabilities to members of that group while removing the role from all other users.

Exam trap

The trap here is that candidates often confuse DLP policies with access control, thinking they can block creation of apps/flows via DLP, when in fact DLP only governs connector usage and data policies, not creation permissions.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy controls data connectors and data sharing between environments, not the ability to create apps or flows; it does not restrict creation permissions. Option C is wrong because disabling the default environment is not supported—the default environment cannot be disabled or deleted; instead, you must manage access through role assignments. Option D is wrong because adding a security group as co-admins grants them administrative privileges (e.g., managing environments, DLP policies), not the specific ability to create apps and flows; the Environment Maker role is the correct role for creation permissions.

27
MCQmedium

Refer to the exhibit. An administrator runs this PowerShell command against a Power Platform environment. What can the administrator conclude?

A.The environment is accessible only to members of the ContosoUsers security group
B.The environment creation failed
C.The environment has no security group assigned
D.The environment is a personal productivity environment
AnswerA

The environmentSecurityGroupName property indicates the security group assigned to the environment.

Why this answer

The PowerShell command `Get-AdminPowerAppEnvironment` returns the environment details, including the `SecurityGroupId` property. If this property is populated with a GUID, it indicates a security group is assigned to the environment, restricting access to its members. Since the exhibit shows a non-null `SecurityGroupId` for the ContosoUsers group, the environment is accessible only to members of that security group.

Exam trap

The trap here is that candidates assume a populated `SecurityGroupId` field means the environment is restricted to that group, but they may confuse it with other properties like `EnvironmentSku` or `Permissions`, or incorrectly think a null value indicates failure rather than no group assignment.

How to eliminate wrong answers

Option B is wrong because the command successfully returned environment details, including a `SecurityGroupId`, which indicates the environment was created and exists. Option C is wrong because the `SecurityGroupId` field is populated with a GUID, meaning a security group is assigned; an empty or null value would indicate no security group. Option D is wrong because a personal productivity environment (e.g., from a Power Apps license) does not have a security group assigned; the presence of a `SecurityGroupId` confirms this is a standard environment with access control.

28
MCQhard

A company has a Power Platform environment that is running low on storage. The administrator needs to free up storage without deleting important data. What should they do first?

A.Disable auditing for all environments
B.Review storage analytics in the Power Platform admin center to identify large entities
C.Delete all audit logs
D.Purchase additional storage capacity
AnswerB

Reviewing storage analytics in the Power Platform admin centre identifies which tables consume the most capacity, letting the administrator target oversized entities before deleting anything. This directly satisfies the stem's constraint of freeing storage without removing important data, since analytics reveals what can be archived or trimmed rather than blindly purged.

Why this answer

The first step in freeing up storage without deleting important data is to identify which entities consume the most space. The Power Platform admin center provides storage analytics that break down storage usage by entity, allowing administrators to make informed decisions about data cleanup or archiving. This approach ensures that only non-essential data is targeted, preserving critical business data.

Exam trap

The trap here is that candidates often jump to disabling auditing or deleting logs as a quick fix, not realizing that storage analytics must be reviewed first to avoid accidentally removing critical data.

How to eliminate wrong answers

Option A is wrong because disabling auditing stops the creation of new audit logs but does not reclaim existing storage; audit logs must be explicitly deleted to free space. Option C is wrong because deleting all audit logs indiscriminately removes potentially important compliance and security records, which violates the requirement to not delete important data. Option D is wrong because purchasing additional storage does not free up existing storage; it only increases capacity, which may not address the root cause of storage inefficiency.

29
Multi-Selecteasy

Which TWO are valid methods to create a new Power Platform environment?

Select 2 answers
A.Using the Power Platform admin center web interface.
B.Using the Power Platform API.
C.Using the Microsoft Teams admin center.
D.Using the Power Apps mobile app.
E.Using the SharePoint admin center.
AnswersA, B

The Power Platform admin center provides a graphical interface for provisioning environments, satisfying the stem's requirement for a valid creation method. An administrator selects New environment, supplies name, region, type and Dataverse options, and the platform provisions it, so no code or scripting is needed.

Why this answer

Option A is correct because the Power Platform admin center (admin.powerplatform.microsoft.com) provides a dedicated Environments page where an administrator can click 'New' and specify environment name, type (Sandbox, Production, Trial, Developer, Teams), region, and Dataverse provisioning. Option B is correct because the Power Platform API exposes environment lifecycle operations, including the CreateEnvironment endpoint (via the BAP/Business Application Platform REST API), enabling programmatic environment creation with appropriate authentication and permissions. Option C is incorrect because the Microsoft Teams admin center manages Teams policies, users, and settings, not Power Platform environment provisioning.

Option D is incorrect because the Power Apps mobile app is a client for running and consuming apps, not an administrative tool for creating environments. Option E is incorrect because the SharePoint admin center manages SharePoint sites, storage, and sharing settings, and has no capability to create Power Platform environments.

Exam trap

PL-900 often tests the confusion between administrative portals (Teams, SharePoint) and the Power Platform admin center, leading candidates to select unrelated admin centers as valid creation methods.

30
MCQeasy

A user reports they cannot create a new Power Apps app in the default environment. They have a Power Apps license. What is the most likely cause?

A.A data loss prevention (DLP) policy is blocking app creation.
B.The user has not been assigned the Environment Maker security role for the default environment.
C.The environment has reached its maximum number of apps.
D.The user does not have a Power Apps license.
AnswerB

Creating apps requires the Environment Maker role, which is separate from licensing. A Power Apps licence alone grants usage rights, but without Environment Maker assigned in the default environment the user cannot create apps there.

Why this answer

The most likely cause is that the user has not been assigned the Environment Maker security role for the default environment. Even with a Power Apps license, a user must be explicitly granted the Environment Maker role in a specific environment (including the default environment) to create apps. Without this role, the user can only run apps, not create or edit them.

Exam trap

The trap here is that candidates often assume having a Power Apps license alone is sufficient to create apps, but the PL-900 exam tests the understanding that environment-level security roles (specifically Environment Maker) are required for app creation, even in the default environment.

How to eliminate wrong answers

Option A is wrong because a data loss prevention (DLP) policy controls which connectors can be used in apps and flows, but it does not block the creation of a new app itself. Option C is wrong because Power Apps environments do not have a hard maximum limit on the number of apps; the limit is on storage and API calls, not app count. Option D is wrong because the question explicitly states the user has a Power Apps license, so lack of license is not the issue.

31
MCQmedium

A Power Platform administrator at Contoso manages a production environment that contains several mission-critical Power Apps canvas apps. The administrator wants to ensure that any change made to an app in this environment is recorded and can be traced back to the user who made it, for audit purposes. Which feature should the administrator enable to meet this requirement?

A.Environment-level activity logging for app and flow modifications, viewable in the Power Platform admin center
B.Managed environments with the 'Share' restriction enabled for the production environment
C.Microsoft Purview Data Loss Prevention policies scoped to the environment's connectors
D.Dataverse auditing at the environment level, configured on the tables used by the apps
AnswerA

The Power Platform admin center provides activity logs for environment-level events, including who created, modified, or deleted apps and flows. Enabling and reviewing these logs lets the administrator trace app changes back to the responsible user. This directly satisfies the requirement of recording and attributing changes made to apps in the production environment.

Why this answer

Environment activity logging in the Power Platform admin center records environment-level operations such as app and flow creation, modification, and deletion, along with the acting user. This gives the administrator the traceability needed to audit who changed mission-critical apps. Dataverse auditing, DLP policies, and managed environment sharing restrictions address data records, connector governance, and sharing scope respectively, not app definition change history.

Exam trap

The trap here is assuming that Dataverse auditing or managed environments automatically produce an audit trail of app and flow definition changes, when that history comes from environment activity logging in the admin center.

32
MCQmedium

A company has a Power Platform environment used for development. The development team needs to deploy a solution to a test environment. What is the recommended approach?

A.Export an unmanaged solution from the development environment and import it into the test environment
B.Manually recreate all components in the test environment
C.Copy the entire development environment to the test environment
D.Export a managed solution from the development environment and import it into the test environment
AnswerD

Managed solutions are the deployment artefact for downstream environments: they are locked, support clean upgrades, and prevent unintended customisation in the test environment. Exporting managed from development and importing into test follows Microsoft's recommended application lifecycle management approach.

Why this answer

Managed solutions are the recommended approach for deploying to non-development environments (e.g., test, UAT, production). A managed solution locks components to prevent direct editing in the target environment, supports lifecycle management (upgrades, patches, and removal), and ensures that only the intended customizations are deployed. Exporting an unmanaged solution (Option A) would leave components editable in the test environment, breaking the managed lifecycle pattern.

Exam trap

The trap here is that candidates often confuse unmanaged and managed solutions, thinking that exporting an unmanaged solution (Option A) is sufficient for deployment, when in fact managed solutions are required for proper lifecycle management and to prevent accidental edits in test/production environments.

How to eliminate wrong answers

Option A is wrong because exporting an unmanaged solution from development and importing it into test would create editable components in the test environment, which violates the recommended managed-solution deployment pattern and can lead to configuration drift. Option B is wrong because manually recreating all components is error-prone, time-consuming, and not a scalable or repeatable approach for environment promotion. Option C is wrong because copying the entire development environment would duplicate all data, settings, and unmanaged customizations, which is not a clean or controlled way to promote a specific solution and can introduce unwanted artifacts.

33
Multi-Selecteasy

A company wants to use Microsoft Copilot Studio to build a chatbot that helps employees reset their passwords. Which TWO components are required? (Choose two.)

Select 2 answers
A.Power Automate to connect to the password reset system
B.Power Virtual Agents (classic)
C.Microsoft Copilot Studio to build and deploy the chatbot
D.Power Apps to create the user interface
E.AI Builder to process natural language
AnswersA, C

Automation is needed to perform the reset.

Why this answer

Power Automate is required to create a flow that connects the chatbot to the password reset system, enabling automated execution of the reset process. Without this integration, the chatbot cannot perform the backend action of resetting the password.

Exam trap

The trap here is that candidates may think AI Builder is required for natural language processing, but Copilot Studio has built-in NLU, making AI Builder unnecessary for this scenario.

34
MCQeasy

A Power Platform administrator needs to monitor the usage of Power Apps and Power Automate across the tenant to identify which environments are consuming the most resources. Which tool should the administrator use?

A.Power BI
B.Microsoft 365 admin center
C.Power Platform admin center
D.Azure Monitor
AnswerC

The Power Platform admin center provides analytics and usage reports for Power Apps, Power Automate, and other services. Administrators can view metrics such as the number of apps and flows per environment, active users, and resource consumption. This centralized tool is designed for tenant-wide monitoring and is the appropriate choice for identifying high-resource environments.

Why this answer

The Power Platform admin center includes built-in analytics and usage reports that show how Power Apps and Power Automate are being used across environments. Administrators can access these reports to see metrics like active users, app launches, and flow runs, helping identify environments with high resource consumption. Other tools like Microsoft 365 admin center or Azure Monitor do not provide this specific Power Platform usage data out of the box.

Exam trap

The trap here is assuming that Power BI or Azure Monitor are required for Power Platform usage monitoring, when the Power Platform admin center already offers native reports without extra configuration.

35
MCQeasy

You are a Power Platform administrator for a non-profit organization. The organization has a single environment used by volunteers and staff. A new volunteer needs to be able to run a specific Power App that manages event registrations, but should not be able to modify the app or access any other resources in the environment. The volunteer has a valid Power Apps license. You need to provide the volunteer with the minimum permissions necessary. What should you do?

A.Share the app directly with the volunteer
B.Create a new environment and add the volunteer there
C.Assign the volunteer the Environment Maker role and share the app
D.Add the volunteer to the System Administrator role
AnswerA

Sharing the app directly grants the volunteer run-only access to that single app, satisfying least privilege. It avoids assigning environment-level roles or maker permissions, so the volunteer cannot edit the app or reach other environment resources.

Why this answer

Sharing the app directly with the volunteer grants run-only access to that specific app without granting environment-wide privileges. The volunteer can use the app but cannot modify it or access other resources, satisfying the least-privilege requirement.

Exam trap

PL-900 often tests the misconception that environment-level roles are needed to run an app, when in fact direct app sharing with run-only permission is the least-privilege approach.

How to eliminate wrong answers

Option B is wrong because creating a new environment is unnecessary overhead and does not by itself grant app access; it also fragments governance. Option C is wrong because Environment Maker allows the user to create and modify apps and resources in the environment, which exceeds the requirement. Option D is wrong because System Administrator grants full control over the environment, far beyond what the volunteer needs.

36
MCQeasy

An admin needs to view the capacity add-ons purchased for a tenant, including AI Builder credits. Where should the admin go?

A.Power Platform admin center > Billing > Licenses
B.Microsoft 365 admin center > Billing > Licenses
C.Power Platform admin center > Resources > Capacity
D.Azure portal > Cost Management + Billing
AnswerC

Capacity add-ons, including AI Builder credits, are consumed tenant-wide rather than per environment, so they are tracked under Resources > Capacity in the Power Platform admin center. This satisfies the requirement to view purchased add-ons for the whole tenant.

Why this answer

The Power Platform admin center is the dedicated management interface for Power Platform resources, including capacity add-ons and AI Builder credits. Under Resources > Capacity, admins can view detailed breakdowns of capacity entitlements, such as database, file, log, and add-on credits like AI Builder service credits. This is the correct location because it provides tenant-level capacity monitoring specific to Power Platform, not general licensing or Azure billing.

Exam trap

The trap here is that candidates confuse the Power Platform admin center's Billing > Licenses (which shows license assignments) with Resources > Capacity (which shows add-on credits), or mistakenly think the Microsoft 365 admin center or Azure portal handles Power Platform capacity management.

How to eliminate wrong answers

Option A is wrong because the Power Platform admin center > Billing > Licenses shows license assignments and subscription details, not capacity add-ons or AI Builder credits. Option B is wrong because the Microsoft 365 admin center > Billing > Licenses manages Microsoft 365 product licenses (e.g., Office 365, Enterprise Mobility + Security), not Power Platform capacity add-ons. Option D is wrong because the Azure portal > Cost Management + Billing handles Azure subscription costs and resource consumption, not Power Platform tenant-level capacity add-ons or AI Builder credits.

37
MCQmedium

A Power Platform administrator is reviewing the security roles in a new environment. The administrator needs to grant a user the ability to create and modify all components within the environment, including managing other users' security roles. Which security role should be assigned?

A.System Customizer.
B.Delegated Administrator.
C.System Administrator.
D.Environment Maker.
AnswerC

The System Administrator security role provides full permissions to manage all components in the environment, including creating and modifying entities, managing security roles, and administering users. It is the highest level of access within an environment and meets the requirement to manage other users' security roles and all components.

Why this answer

The System Administrator security role in a Power Platform environment grants full control over all components and settings, including the ability to manage security roles for other users. It is the only role among the options that provides this level of administrative access within the environment. The Environment Maker and System Customizer roles have more limited permissions, and Delegated Administrator is a tenant-level role, not an environment-level one.

Exam trap

The trap here is confusing the System Customizer role with the System Administrator role, as both can modify components, but only System Administrator can manage security roles.

38
MCQeasy

A Power Platform administrator needs to view the capacity consumption for the tenant, including how much Dataverse storage and Power Platform request capacity is being used. Where should the administrator go?

A.The Azure portal, under Cost Management + Billing.
B.The Power Platform admin center, under Analytics > Capacity.
C.The Microsoft 365 admin center, under Billing > Licenses.
D.The Microsoft Purview compliance portal, under Reports.
AnswerB

The Power Platform admin center includes a Capacity page under Analytics that displays detailed information about Dataverse storage, Power Platform requests, and other capacity metrics for the tenant. This is the central location to monitor and manage capacity consumption, making it the correct choice.

Why this answer

The Power Platform admin center is the dedicated portal for managing Power Platform environments and capacity. The Capacity page under Analytics provides a comprehensive view of Dataverse storage, Power Platform requests, and other add-on capacities. This is the correct place for administrators to monitor tenant-wide capacity usage.

Exam trap

The trap here is assuming that capacity information is in the Microsoft 365 admin center or Azure portal, but it is exclusively in the Power Platform admin center.

39
Multi-Selecthard

An organization is preparing for a Power Platform rollout. They need to ensure that only licensed users can create new environments, and that environment creation is audited. Additionally, they want to restrict which connectors can be used in production environments. Which THREE capabilities should they use?

Select 3 answers
A.Data Loss Prevention (DLP) policies
B.Microsoft 365 admin center to assign Power Platform licenses
C.Power Platform Admin Center environment creation settings
D.Power Virtual Agents bot
E.Power Apps mobile app
AnswersA, B, C

DLP policies can block specific connectors in production environments.

Why this answer

Data Loss Prevention (DLP) policies allow administrators to block or restrict specific connectors (e.g., HTTP, custom connectors) in production environments, ensuring sensitive data is not exposed through unauthorized integrations. This directly addresses the requirement to restrict which connectors can be used in production environments.

Exam trap

The trap here is that candidates may confuse Power Virtual Agents bot (Option D) as a governance tool, but it is solely a chatbot builder with no administrative role in environment management or connector restrictions.

40
MCQmedium

An organization uses Power Apps portals to allow external customers to submit support tickets. The portal uses Microsoft Entra ID for authentication. The security team wants to require multi-factor authentication (MFA) for external portal users. What is the best approach?

A.Create a Conditional Access policy in Microsoft Entra ID that requires MFA for the portal application
B.Enable MFA for all Microsoft Entra ID users
C.Use a third-party identity provider that supports MFA
D.Configure MFA in the Power Apps portal authentication settings
AnswerA

A Conditional Access policy in Microsoft Entra ID enforces MFA at the identity provider for the portal application, covering all external users regardless of client. Configuring MFA per-app or per-user would not scale or satisfy the requirement to require MFA for external portal users.

Why this answer

Conditional Access in Microsoft Entra ID is the supported, centralized mechanism to require MFA for a specific application such as a Power Apps portal. By scoping the policy to the portal enterprise application and setting the grant control to 'Require multi-factor authentication', external users authenticating via Entra ID are challenged for MFA without affecting other apps. This is the recommended approach because portal authentication is delegated to Entra ID, so MFA must be enforced at the identity provider layer.

Exam trap

PL-900 often tests the misconception that MFA can be configured directly inside Power Apps portal settings — in reality, MFA is always enforced by the identity provider via Conditional Access or security defaults.

How to eliminate wrong answers

Option B is wrong because enabling MFA for all Entra ID users is overly broad and would impact internal users and unrelated applications, not just the portal. Option C is wrong because introducing a third-party IdP adds unnecessary complexity and cost when Entra ID already supports MFA natively for the portal. Option D is wrong because Power Apps portals do not have a native MFA configuration setting — authentication and MFA are governed by the underlying identity provider (Entra ID, AD FS, or a social IdP), not by portal settings.

41
MCQeasy

An organization uses Power Automate flows that connect to Microsoft Dataverse and SharePoint. The administrator needs to ensure that only specific connectors can be used together. What should they configure?

A.Enable solution component isolation
B.Configure a Data Loss Prevention (DLP) policy
C.Create an environment security group
D.Turn on auditing for the environment
AnswerB

A Data Loss Prevention policy defines connector groups and blocks combinations spanning them, so Dataverse and SharePoint connectors can be restricted to permitted groupings. This satisfies the stem's constraint by enforcing which connectors may be used together within the environment.

Why this answer

Data Loss Prevention (DLP) policies in the Power Platform allow administrators to classify connectors into Business, Non-Business, and Blocked groups, and to define which connectors can be used together within a single flow or app. This directly enforces the requirement that only specific connectors can be combined, preventing data from flowing between incompatible services such as Dataverse and a personal social media connector.

Exam trap

PL-900 often tests the confusion between governance controls (DLP) and access controls (security groups), causing candidates to pick environment security groups when the requirement is about restricting connector combinations.

How to eliminate wrong answers

Option A is wrong because solution component isolation relates to ALM and moving components between environments, not to restricting connector combinations. Option C is wrong because an environment security group controls which users can access an environment, not which connectors can be combined. Option D is wrong because auditing only records activity for compliance and investigation; it does not restrict or govern connector usage.

42
MCQeasy

A Power Platform administrator needs to monitor the usage of Power Apps and Power Automate across the organization to identify which environments have the highest adoption. Which built-in tool should the administrator use?

A.Power BI Desktop with the Power Platform connector.
B.Microsoft Purview Compliance Portal.
C.Microsoft 365 admin center Reports.
D.Power Platform admin center Analytics.
AnswerD

The Power Platform admin center provides built-in analytics dashboards that show usage metrics for Power Apps, Power Automate, and other services. Administrators can view adoption trends, active users, and environment-level usage. This tool is specifically designed for monitoring and reporting, making it the correct choice for identifying high-adoption environments.

Why this answer

The Power Platform admin center includes built-in Analytics dashboards that provide usage data for Power Apps and Power Automate. These dashboards show metrics such as active users, app launches, and flow runs, and can be filtered by environment. This is the most direct and built-in method for an administrator to monitor adoption across environments without additional tools or configuration.

Exam trap

The trap here is assuming that Microsoft 365 admin center or Purview includes Power Platform usage analytics, but those tools focus on other services and compliance, not Power Platform adoption.

43
Multi-Selecteasy

Which TWO of the following are valid environment types in Power Platform?

Select 2 answers
A.Development
B.Production
C.Sandbox
D.Trial
E.Preview
AnswersB, C

Production is a standard environment type.

Why this answer

Production and Sandbox are both valid environment types in Power Platform. Production environments are intended for live, end-user applications and data, while Sandbox environments are isolated, non-production environments used for development, testing, and training. Both support the full set of Power Platform capabilities, including Dataverse, Power Apps, Power Automate, and Power Virtual Agents.

Exam trap

The trap here is that candidates often confuse 'Development' as a separate environment type, but Power Platform only uses Production, Sandbox, Trial, and Preview as environment types, with Sandbox serving the development role.

44
MCQmedium

A company is using Power Automate flows that connect to multiple third-party services. The security administrator wants to ensure that no sensitive data is sent to unauthorized external services. Which feature should be used to enforce this requirement?

A.Create and apply Data Loss Prevention (DLP) policies.
B.Enable audit logging in the Power Platform admin center.
C.Configure environment routing rules.
D.Use the Power Platform Copilot to monitor flows.
AnswerA

DLP policies in Power Platform define connector classification into Business, Non-Business and Blocked groups, then enforce which connectors a flow may combine. This directly prevents sensitive data reaching unauthorised external services, satisfying the administrator's requirement to block exfiltration across third-party connections.

Why this answer

Data Loss Prevention (DLP) policies in Power Platform define which connectors are Business, Non-Business, or Blocked, and prevent flows from combining connectors across groups — thereby stopping sensitive data from flowing to unauthorized external services. This is the purpose-built governance control for restricting connector usage across flows and apps.

Exam trap

The trap is confusing monitoring/auditing features (which detect after the fact) with preventive controls like DLP that actually block unauthorized connector combinations.

How to eliminate wrong answers

Option B is wrong because audit logging only records activity for later review; it does not prevent data from being sent to unauthorized services. Option C is wrong because environment routing rules govern how makers are directed to environments during creation, not connector-level data flow restrictions. Option D is wrong because Copilot is an assistive AI feature for authoring and does not enforce connector governance or DLP.

45
MCQmedium

A Power Platform admin needs to ensure that all environments have a backup policy that automatically creates backups every 24 hours. What is the default backup frequency for Dataverse environments?

A.Every 24 hours
B.Only for paid environments, there is no default schedule.
C.Every 12 hours
D.Every 48 hours
AnswerA

Dataverse automatically creates system backups every 24 hours.

Why this answer

The default backup frequency for Dataverse environments is every 24 hours, which ensures automatic system backups are created daily without requiring manual configuration. This policy applies to all environments, including trial and production, unless a custom backup schedule is explicitly set by an administrator.

Exam trap

The trap here is that candidates may assume backups are only for paid environments or that the default frequency is shorter (12 hours) due to common industry practices, but Microsoft's default for Dataverse is explicitly 24 hours across all environment types.

How to eliminate wrong answers

Option B is wrong because the default backup schedule applies to all Dataverse environments, not just paid ones; even trial environments receive automatic backups every 24 hours. Option C is wrong because the default interval is 24 hours, not 12 hours; a 12-hour frequency would require custom configuration. Option D is wrong because the default interval is 24 hours, not 48 hours; a 48-hour frequency would leave a longer gap between backups and is not the default.

46
MCQhard

The exhibit shows a DLP policy configuration for a Power Platform environment. Which connector is allowed for business use?

A.Outlook
B.Twitter
C.Facebook
D.SharePoint
AnswerD

SharePoint is in the Business data group under this DLP policy, so it is allowed for business use.

Why this answer

SharePoint is classified as 'Business' in the DLP policy because it is a Microsoft-owned enterprise service that supports data loss prevention (DLP) actions like blocking, monitoring, or restricting data flow. The exhibit shows SharePoint under the 'Business' data group, meaning it is allowed for business use without triggering policy violations. In contrast, Outlook, Twitter, and Facebook are placed in the 'Non-Business' group, which blocks their connectors from being used in apps and flows within this environment.

Exam trap

The trap here is that candidates assume all Microsoft-owned connectors (like Outlook) are automatically 'Business' by default, but DLP policies are environment-specific and can be customized by administrators to reclassify connectors into Non-Business groups.

How to eliminate wrong answers

Option A is wrong because Outlook is listed under the 'Non-Business' data group in the exhibit, which means its connector is blocked for business use. Option B is wrong because Twitter is also in the 'Non-Business' group, preventing its connector from being used in business flows. Option C is wrong because Facebook is likewise categorized as 'Non-Business', so its connector is disallowed for business purposes.

47
MCQhard

A large enterprise uses Power Platform with multiple environments. They need to enforce a policy that blocks all Canvas apps from using the 'Twitter' connector, but only in the 'Production' environment. What should the administrator do?

A.Create a DLP policy at the tenant level and set the 'Twitter' connector to 'Blocked'
B.Disable the 'Twitter' connector in the Power Platform admin center for the Production environment
C.Create an environment-level DLP policy for the Production environment and set 'Twitter' to 'Blocked'
D.Use the 'Set Connector' API to disable the connector for the Production environment
AnswerC

DLP policies can be scoped to a single environment, so an environment-level policy applied to Production blocks the Twitter connector there while leaving other environments unaffected. This satisfies the stem's constraint of restricting the block to Production only.

Why this answer

Environment-level DLP policies allow administrators to apply connector restrictions to specific environments, such as blocking the 'Twitter' connector only in 'Production' while leaving it available in other environments. This granular control is essential for enforcing governance without affecting development or testing environments.

Exam trap

The trap here is that candidates may assume tenant-level policies are the only option or that connectors can be disabled directly in the admin center, but the correct approach requires understanding that environment-level DLP policies provide the necessary granularity.

How to eliminate wrong answers

Option A is wrong because a tenant-level DLP policy applies to all environments, not just the 'Production' environment, which would block the 'Twitter' connector everywhere. Option B is wrong because the Power Platform admin center does not provide a direct toggle to disable a specific connector per environment; connector blocking is managed through DLP policies, not a simple disable switch. Option D is wrong because the 'Set Connector' API is not a supported method for disabling connectors in Power Platform; DLP policies are the intended mechanism for controlling connector usage.

48
MCQmedium

A company is deploying Power Virtual Agents (now Copilot Studio) chatbots across multiple departments. Each department needs its own environment to manage chatbots independently. However, the company wants to share a common set of entities and workflows across all environments. Which approach should the administrator take?

A.Create a single environment for all departments and use security roles to isolate chatbots
B.Use Power Apps component library to share components across environments
C.Create a shared environment for common components and link each department environment to it
D.Create a separate environment per department and deploy managed solutions containing the common components
AnswerD

Managed solutions are the supported mechanism for distributing common components across environments while preventing downstream modification. Creating one environment per department preserves independent chatbot management, and deploying the shared entities and workflows as a managed solution satisfies the stem's requirement for commonality without sacrificing departmental autonomy.

Why this answer

Managed solutions allow you to package common components (entities, workflows) and deploy them to multiple environments, ensuring consistency while maintaining departmental isolation. Each department gets its own environment for independent chatbot management, and the shared components are installed via managed solutions that cannot be modified, preserving the common baseline.

Exam trap

The trap here is that candidates confuse environment-level isolation with component sharing, assuming a single environment with security roles or a linked environment is sufficient, when the correct pattern requires deploying managed solutions to each environment.

How to eliminate wrong answers

Option A is wrong because using a single environment with security roles does not provide true isolation for chatbot management; security roles control data access but not component-level separation, and all chatbots would share the same entities and workflows, leading to potential conflicts. Option B is wrong because Power Apps component libraries are designed for sharing UI components (e.g., controls, screens) across canvas apps, not for deploying backend entities or workflows across environments. Option C is wrong because Power Platform does not support linking environments to a shared environment for common components; the correct mechanism is to use managed solutions to deploy components into each environment, not a runtime link.

49
MCQmedium

An administrator configures a Data Loss Prevention (DLP) policy with the scope set to 'All environments' and places selected connectors in the 'Blocked' group. What will be the result of this policy?

A.The connectors are allowed but audited
B.The connectors are blocked only in production environments
C.The connectors are blocked in all environments
D.The connectors are blocked except for the default environment
AnswerC

Scoping the DLP policy to 'All environments' applies the connector classification everywhere, so placing connectors in the 'Blocked' group prevents their use across every environment. This satisfies the stem's stated scope, rather than restricting blocking to a single environment.

Why this answer

A DLP policy scoped to 'All environments' applies its connector classification across every Power Platform environment in the tenant. When connectors are placed in the 'Blocked' group, any app or flow using those connectors is prevented from running in any environment, including the default one. The scope setting directly determines where the policy's restrictions take effect.

Exam trap

The trap is misreading the scope — candidates assume 'All environments' excludes the default environment or only applies to production, but it applies to every environment including the default one.

How to eliminate wrong answers

Option A is wrong because 'Blocked' is a restrictive classification, not an audit-only one; audited connectors would be in the 'Business' or 'Non-business' group with audit-only settings. Option B is wrong because 'All environments' explicitly includes every environment, not just production — there is no production-only scope in this policy. Option D is wrong because 'All environments' includes the default environment; there is no exception carved out for the default environment in this configuration.

50
MCQhard

A Power Platform administrator discovers that a developer has deployed a canvas app to production that connects to both SharePoint and an unapproved third-party REST API using a custom connector. The security team requires that custom connectors be reviewed before production use, while still allowing makers to prototype them in a sandbox environment. What should the administrator configure to meet this requirement?

A.Environment security roles that remove the Environment Maker role from the developer in production
B.A Data Loss Prevention policy scoped to the production environment that places the custom connector in the Blocked group and the sandbox environment in a separate policy that allows it
C.Connector consent settings that require admin approval for the custom connector tenant-wide
D.A tenant-wide DLP policy that places the custom connector in the Blocked group for all environments
AnswerB

DLP policies can be scoped to specific environments, so the custom connector can be Blocked in production while a different policy allows it in the sandbox. This prevents the unapproved connector from running in production yet preserves prototyping capability. It directly matches the requirement to review custom connectors before production use while allowing sandbox experimentation.

Why this answer

Data Loss Prevention policies can be scoped to individual environments, allowing the administrator to block the custom connector in production while a separate policy permits it in the sandbox. This enforces the security team's review requirement without eliminating prototyping. A tenant-wide block, role removal, and tenant-level connector consent do not provide the environment-specific control needed, and some do not affect the already deployed app.

Exam trap

The trap here is assuming DLP policies are always tenant-wide, when they can actually be scoped to specific environments, which is exactly what allows blocking a connector in production while permitting it in a sandbox.

51
MCQmedium

An organization wants to ensure that all Power Platform solutions in production environments are tracked and changes are approved. What should the administrator implement?

A.Data Loss Prevention (DLP) policies
B.Environment security groups
C.Disable the 'Create personal productivity environments' setting
D.Managed solutions with application lifecycle management (ALM)
AnswerD

Managed solutions lock components, preventing unmanaged edits in production, while ALM enforces approval gates through pipelines and environments. This satisfies the requirement that production solutions be tracked and changes approved, since unmanaged customisation bypasses governance entirely.

Why this answer

Managed solutions with application lifecycle management (ALM) ensure that all Power Platform solutions in production environments are tracked and changes are approved by enforcing version control, solution layering, and controlled deployment through environments. This approach uses solution components and environment segmentation to prevent unapproved modifications and maintain an audit trail.

Exam trap

The trap here is that candidates often confuse DLP policies or security groups with change management, but only managed solutions with ALM provide the structured tracking and approval workflow required for production governance.

How to eliminate wrong answers

Option A is wrong because Data Loss Prevention (DLP) policies control data flow between connectors and prevent data exfiltration, but they do not track or approve changes to solutions. Option B is wrong because environment security groups manage user access and permissions to environments, not the tracking or approval of solution changes. Option C is wrong because disabling the 'Create personal productivity environments' setting only prevents users from creating their own environments, but does not enforce change tracking or approval for production solutions.

52
MCQmedium

A Power Platform administrator needs to delegate the ability to create and manage environments to a specific user without granting full Power Platform administrator privileges. The administrator wants to follow the principle of least privilege. What should the administrator do?

A.Assign the Environment Admin role for the environments and the Environment Creator role at the tenant level.
B.Assign the Environment Admin role for each environment the user should manage.
C.Assign the Power Platform Administrator role to the user in Microsoft Entra ID.
D.Assign the Environment Creator role in the Power Platform admin center.
AnswerA

Combining the Environment Creator role at the tenant level with Environment Admin roles for specific environments allows the user to create new environments and manage the ones they are responsible for. This follows least privilege because the user does not receive full Power Platform Administrator rights but can still perform the required tasks.

Why this answer

To delegate environment creation and management without full admin rights, the administrator should assign the Environment Creator role at the tenant level and Environment Admin roles for the specific environments. This combination provides the necessary permissions while adhering to least privilege, as the user cannot manage unrelated environments or tenant-wide policies.

Exam trap

The trap here is assuming that a single role can grant both environment creation and management; in reality, these are separate permissions that must be combined.

53
Multi-Selectmedium

A company wants to enforce data loss prevention (DLP) policies for Power Automate flows. Which TWO actions can the administrator perform?

Select 2 answers
A.Allow users to bypass DLP policies with administrator approval
B.Block specific connectors from being used in flows
C.Create a custom DLP policy for a specific environment
D.Assign DLP policies to specific users
E.Inherit the tenant-level DLP policy for all environments
AnswersB, C

Blocking connectors is a common DLP action.

Why this answer

Administrators can block specific connectors from being used in Power Automate flows as part of a DLP policy, preventing data from being shared with unauthorized services. Option C is correct because DLP policies can be scoped to a specific environment, allowing granular control over connector usage within that environment. This enables the administrator to enforce data protection rules tailored to different business contexts.

Exam trap

The trap here is that candidates often confuse environment-level DLP policy assignment with user-level assignment, or assume that tenant-level policies are automatically inherited by all environments, when in fact each environment can have its own independent DLP policy.

54
MCQmedium

An organization uses Microsoft Power Platform and wants to enforce data loss prevention (DLP) policies across all environments. They need to block the use of a specific third-party connector in all environments. What should the administrator do?

A.Create a DLP policy for each environment and block the connector
B.Create a custom connector with the same name and block it
C.Remove the connector from the default solution
D.Create a tenant-level DLP policy that blocks the connector
AnswerD

A tenant-level DLP policy applies across every environment within the tenant, so blocking the third-party connector there satisfies the requirement to restrict it everywhere. Environment-scoped policies would only cover individual environments, leaving others unprotected. Tenant-wide scope is the mechanism that enforces the block universally.

Why this answer

DLP policies in Microsoft Power Platform can be configured at the tenant level to apply across all environments. By creating a tenant-level DLP policy and blocking the specific third-party connector, the administrator ensures consistent enforcement without needing to manage individual environment policies. This approach centralizes control and prevents the connector from being used in any environment.

Exam trap

The trap here is that candidates often assume DLP policies must be created per environment, overlooking the tenant-level scope that provides centralized enforcement across all environments.

How to eliminate wrong answers

Option A is wrong because creating a DLP policy for each environment is inefficient and error-prone; it requires manual replication across environments and does not guarantee uniform enforcement if environments are added or missed. Option B is wrong because creating a custom connector with the same name does not block the original third-party connector; custom connectors are separate entities and blocking a custom connector does not affect the built-in or certified connector. Option C is wrong because removing a connector from the default solution does not block its use; connectors are not managed through solutions in that way, and removal from a solution only affects solution components, not connector availability in environments.

55
Multi-Selectmedium

A Power Platform administrator is configuring a new environment for a team that will use both Power Apps and Power Automate. The administrator needs to ensure that the team can only use a specific set of connectors and that data cannot be shared between certain connectors. Which two actions should the administrator take? (Choose two.)

Select 2 answers
A.Configure the environment's security group to include only the team members who need access.
B.Use the Power Platform admin center to set the environment's region to a specific geography.
C.Apply the DLP policy to the environment so that it enforces the connector restrictions for all apps and flows within it.
D.Create a data loss prevention (DLP) policy that defines connector groups and blocks connectors from different groups from being used together.
E.Assign the Environment Maker security role to all team members.
AnswersC, D

After creating a DLP policy, you must apply it to the specific environment to enforce the connector groupings and restrictions. Applying the policy ensures that the rules are active for all apps and flows in that environment, thereby preventing data sharing between the defined connector groups as required.

Why this answer

To restrict connector usage and prevent data sharing between certain connectors, the administrator must create a DLP policy that defines connector groups and blocks cross-group usage, and then apply that policy to the environment. These two actions together enforce the desired governance. Other actions, such as assigning roles or setting region, do not address connector-level restrictions or data flow control.

Exam trap

The trap here is thinking that assigning security roles or setting region can control connector usage, when only DLP policies applied to the environment govern which connectors can be used together.

56
Multi-Selecthard

Which THREE components are part of the Power Platform environment lifecycle management?

Select 3 answers
A.Environment creation
B.Environment deletion
C.Creating users in Microsoft Entra ID
D.Environment backup and restore
E.Publishing Power BI reports
AnswersA, B, D

Creating environments is a key lifecycle operation.

Why this answer

Environment creation is a core component of Power Platform environment lifecycle management because it establishes the isolated container where apps, flows, and data reside. The lifecycle begins when an administrator provisions a new environment, which sets up a dedicated Dataverse database, security boundaries, and resource limits. Without creation, no subsequent lifecycle operations (backup, restore, deletion) can occur.

Exam trap

The trap here is that candidates confuse operational tasks (like creating users or publishing reports) with environment lifecycle management, which strictly covers the creation, deletion, backup, and restore of the environment itself, not activities that occur within it.

57
MCQmedium

A multinational corporation uses Power Platform extensively. They have multiple environments: DEV, TEST, UAT, STAGING, and PROD. A developer accidentally published a Power App that connects to a SQL Server database using an unapproved connector in the PROD environment. The organization has strict data governance policies that require all connections to use approved connectors only. The admin needs to block this connector in PROD while still allowing it in other environments. What should the admin do?

A.Create a tenant-level DLP policy that blocks the connector for all environments.
B.Remove the developer's permissions to the PROD environment.
C.Delete the Power App from PROD.
D.Create an environment-level DLP policy for PROD that blocks the connector.
AnswerD

Environment-level DLP policies scope connector blocking to a single environment, so PROD can block the unapproved SQL connector while DEV, TEST, UAT and STAGING remain unaffected. Tenant-level policies would apply everywhere, failing the requirement to allow it elsewhere. This satisfies the stem's constraint of blocking in PROD only.

Why this answer

Environment-level DLP policies in Power Platform apply only to a specific environment, so creating one for PROD that blocks the unapproved connector restricts it there while leaving DEV, TEST, UAT, and STAGING unaffected. This precisely meets the requirement to block the connector only in PROD. Tenant-level policies would affect all environments, which is too broad.

Exam trap

The trap is defaulting to a tenant-level DLP policy because it's the most familiar control; candidates overlook that environment-level policies are required when governance must differ between PROD and non-PROD environments.

How to eliminate wrong answers

Option A is wrong because a tenant-level DLP policy applies across all environments, blocking the connector everywhere and violating the requirement to allow it in non-PROD environments. Option B is wrong because removing the developer's PROD permissions does not block the connector for other users and is a personnel control, not a data governance control. Option C is wrong because deleting the app removes the symptom but does not prevent the connector from being used again in PROD, and it destroys a business app rather than enforcing policy.

58
MCQmedium

A company uses Microsoft Power Platform and requires that all environment creation requests go through an approval process. The security team wants to prevent non-admins from creating trial environments. What should the administrator configure?

A.In Power Platform Admin Center, set 'Disable trial environments created by non-admins' to Yes
B.Assign users to an environment group with restricted permissions
C.In Power Apps settings, disable 'Allow users to create environments'
D.Create a Data Loss Prevention (DLP) policy that blocks trial environments
AnswerA

This setting prevents non-admins from creating trial environments.

Why this answer

The Power Platform Admin Center provides a dedicated tenant-level setting called 'Disable trial environments created by non-admins' that, when set to 'Yes', prevents users without administrative privileges from creating trial environments. This directly addresses the security team's requirement to block non-admins from creating trial environments, as it enforces an approval-based control at the environment creation level.

Exam trap

The trap here is that candidates often confuse DLP policies with environment lifecycle controls, assuming DLP can block environment creation, when in reality DLP only governs data connectors and policies across environments, not provisioning actions.

How to eliminate wrong answers

Option B is wrong because environment groups (or environment routing groups) do not exist in Power Platform; this is a fabricated concept and cannot restrict environment creation permissions. Option C is wrong because the setting 'Allow users to create environments' in Power Apps settings is a legacy control that only applies to the default environment and does not specifically block trial environments; it also does not enforce an approval process. Option D is wrong because Data Loss Prevention (DLP) policies control data movement and connector usage across environments, not environment creation or trial environment provisioning; DLP policies cannot block the creation of environments.

59
MCQmedium

An organization wants to allow external partners to access specific Power Apps and data without granting them full access to the tenant. What should they configure?

A.Use Microsoft Intune to manage partner devices.
B.Create a data loss prevention (DLP) policy that allows external sharing.
C.Invite partners as guest users in Microsoft Entra ID and assign them appropriate security roles in the Power Platform environment.
D.Share the app URL with the partners and ask them to sign in with their own accounts.
AnswerC

Guest accounts in Microsoft Entra ID grant external partners scoped access without tenant-wide rights, and Power Platform security roles then limit them to the specific apps and data required, satisfying the constraint of no full tenant access.

Why this answer

Inviting external partners as guest users in Microsoft Entra ID (formerly Azure AD) and assigning them appropriate security roles in the Power Platform environment is the standard method for providing controlled, least-privilege access to specific Power Apps and their underlying data sources. This approach leverages Microsoft Entra B2B collaboration to create guest identities, which can then be granted access to specific environments and resources without giving them full tenant-level permissions.

Exam trap

The trap here is that candidates often confuse sharing the app URL (Option D) with a valid access method, not realizing that Power Apps requires authenticated users with appropriate permissions in the environment, and simply providing a URL does not grant access unless the user is already a guest or member of the tenant.

How to eliminate wrong answers

Option A is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) solution for managing devices and apps, not a mechanism for granting external users access to Power Apps or data. Option B is wrong because a data loss prevention (DLP) policy controls how data can be shared between connectors and prevents data exfiltration, but it does not provide authentication or authorization for external users to access Power Apps. Option D is wrong because sharing the app URL and asking partners to sign in with their own accounts would require those accounts to be recognized by the tenant (e.g., as guest users) or the app to be publicly accessible, which would bypass security controls and is not a supported method for secure external access.

60
MCQmedium

An organization wants to ensure that when a Power Apps canvas app is shared with a user, the user can run the app but cannot edit it or share it with others. The app is in a production environment. What should the administrator or maker do?

A.Publish the app as a managed solution and assign the user the 'System Customizer' role.
B.Add the user to a security role that has only read access to the app's data source.
C.Share the app with the user and assign the 'Can use' permission only.
D.Share the app with the user and assign the 'Can edit' permission, then remove the user's Environment Maker role.
AnswerC

When sharing a canvas app, you can assign either 'Can use' or 'Can edit' permissions. 'Can use' allows the user to run the app but not modify it or share it. This directly meets the requirement to restrict the user to running the app only, without editing or sharing capabilities.

Why this answer

Canvas app sharing permissions are managed directly when sharing the app. The 'Can use' permission allows users to run the app but not edit or reshare it. 'Can edit' grants modification rights. Security roles and solution packaging do not control app-level sharing permissions, so they are not the correct mechanisms for this requirement.

Exam trap

The trap here is confusing data source security roles or solution types with app sharing permissions; only the 'Can use' permission restricts a user to running the app without editing or sharing.

61
MCQhard

A company has multiple Power Platform environments. They want to automatically apply consistent settings (e.g., DLP policies, audit settings) to all new environments. What should they do?

A.Use PowerShell scripts to configure each environment after creation.
B.Use Azure Blueprints to define and apply a set of Azure resources.
C.Create an environment group in the Power Platform admin center and assign policies to the group.
D.Use Microsoft Intune to enforce settings on Power Platform environments.
AnswerC

Environment groups in the Power Platform admin center let administrators assign DLP policies and audit settings once, with those rules automatically inherited by every environment added to the group, including newly created ones. This satisfies the requirement for consistent automatic configuration.

Why this answer

Environment groups in the Power Platform admin center allow administrators to define a set of policies (such as DLP policies and audit settings) that are automatically applied to all environments within the group, including newly created ones. This provides a centralized, no-code method to enforce consistent governance across multiple environments without manual intervention.

Exam trap

The trap here is that candidates may confuse Azure Blueprints (which manage Azure infrastructure) with Power Platform environment governance, or think that PowerShell scripting is the only way to automate settings, overlooking the built-in environment group feature that provides automatic, policy-driven consistency.

How to eliminate wrong answers

Option A is wrong because using PowerShell scripts to configure each environment after creation is a manual, reactive approach that does not automatically apply settings to new environments as they are created, and it requires ongoing maintenance and scripting expertise. Option B is wrong because Azure Blueprints are designed to orchestrate the deployment of Azure resources (e.g., VMs, databases) and are not applicable to managing Power Platform environment settings like DLP policies or audit configurations. Option D is wrong because Microsoft Intune is a mobile device management (MDM) and mobile application management (MAM) tool for managing devices and apps, not for enforcing settings on Power Platform environments.

62
MCQhard

A financial services company uses Power Automate to process loan applications. The flow uses the ‘When a new email arrives’ trigger from a shared mailbox. The flow recently stopped working after an admin changed the mailbox permissions. What is the most likely cause?

A.The mailbox exceeded its storage limit
B.The mailbox connection lost permissions to access the mailbox
C.The flow owner's Power Automate license was deleted
D.The flow was transferred to another owner
AnswerB

The trigger authenticates using the connection's stored credentials against the shared mailbox. When the administrator altered mailbox permissions, the connection principal lost access, so the trigger can no longer poll the mailbox and the flow stops firing.

Why this answer

The flow uses the 'When a new email arrives' trigger, which relies on a connection to the shared mailbox. When an admin changes mailbox permissions, the existing connection loses its authorization to access the mailbox, causing the trigger to fail. This is the most direct cause because the connection object in Power Automate must have valid permissions to read emails from the specified mailbox.

Exam trap

The trap here is that candidates may confuse a permissions issue with a storage limit or license problem, but the trigger's dependency on a valid connection object makes permission changes the immediate and most likely cause.

How to eliminate wrong answers

Option A is wrong because exceeding the mailbox storage limit would cause new emails to be rejected or bounce, but the flow trigger would still attempt to run and fail with a different error (e.g., mailbox full), not a permissions-related failure. Option C is wrong because deleting the flow owner's Power Automate license would disable the flow entirely or prevent it from being saved/run, but the scenario specifies the flow stopped working after a permissions change, not a license change. Option D is wrong because transferring the flow to another owner does not inherently break the mailbox connection; the new owner would need to re-authenticate, but the trigger failure is directly tied to the permissions change, not ownership transfer.

63
MCQeasy

An organization wants to enable Microsoft Copilot Studio (formerly Power Virtual Agents) to answer questions from employees about company policies. The chatbot must only use internal company documents stored in SharePoint as its knowledge source. Which configuration should the administrator use?

A.Enable the 'Use generative AI' feature in the Power Platform admin center
B.Deploy a custom connector to SharePoint
C.Create a Power Automate flow to fetch data from SharePoint and pass it to the chatbot
D.Add a SharePoint knowledge source in Copilot Studio and configure authentication to use the company's Microsoft Entra ID
AnswerD

Copilot Studio's SharePoint knowledge source indexes only the specified internal document libraries, and Microsoft Entra ID authentication ensures the bot queries content the signed-in employee is permitted to see. This confines answers to company policy documents rather than public web results.

Why this answer

Microsoft Copilot Studio allows administrators to add SharePoint as a knowledge source directly, enabling the chatbot to retrieve answers from internal documents without custom development. Configuring authentication with Microsoft Entra ID ensures that only authorized users can access the company policies, maintaining security and compliance.

Exam trap

The trap here is that candidates may overcomplicate the solution by thinking a custom connector or Power Automate flow is required, when in fact Copilot Studio's native SharePoint integration handles the connection directly.

How to eliminate wrong answers

Option A is wrong because the 'Use generative AI' feature in the Power Platform admin center is a tenant-level setting that enables AI capabilities across environments, but it does not directly connect a chatbot to SharePoint documents as a knowledge source. Option B is wrong because deploying a custom connector to SharePoint is unnecessary and overly complex; Copilot Studio natively supports SharePoint as a knowledge source without requiring custom connectors. Option C is wrong because creating a Power Automate flow to fetch data from SharePoint and pass it to the chatbot introduces unnecessary latency and complexity, whereas Copilot Studio can directly query SharePoint using its built-in integration.

64
MCQhard

A Power Platform administrator is configuring data loss prevention (DLP) policies. The company uses Power Automate flows that connect to Microsoft SharePoint and Microsoft Teams. The security team wants to block any flow from sending data from SharePoint to unsanctioned third-party services. Which DLP policy configuration should the administrator apply?

A.Create a policy that only applies to non-production environments
B.Classify SharePoint as Business and all third-party services as Blocked
C.Classify SharePoint as Business and all third-party services as Non-Business
D.Classify all connectors as Blocked
AnswerB

Classifying SharePoint as Business and third-party services as Blocked satisfies the stem's constraint: DLP connector classification prevents cross-group data movement. Power Automate blocks any flow combining a Business connector with a Blocked connector, so SharePoint data cannot reach unsanctioned services. Blocked connectors are excluded entirely, enforcing the security team's requirement.

Why this answer

DLP policies in Power Platform allow administrators to classify connectors into Business, Non-Business, and Blocked categories. By classifying SharePoint as Business and all third-party services as Blocked, the administrator ensures that no flow can send data from SharePoint to unsanctioned third-party connectors, as blocked connectors cannot be used in any flow that also uses a Business connector. This directly enforces the security team's requirement to prevent data exfiltration to unsanctioned services.

Exam trap

The trap here is that candidates often confuse 'Non-Business' with 'Blocked', not realizing that Non-Business connectors can still be used in flows alongside Business connectors, whereas only the Blocked category prevents data from being sent to those services entirely.

How to eliminate wrong answers

Option A is wrong because applying a policy only to non-production environments would not protect production flows that connect SharePoint to unsanctioned third-party services, leaving the security requirement unmet. Option C is wrong because classifying third-party services as Non-Business would still allow flows to use both Business (SharePoint) and Non-Business connectors in the same flow, which does not block data from being sent to those services—only the 'Blocked' category prevents connector usage entirely. Option D is wrong because classifying all connectors as Blocked would prevent all flows from using any connector, including SharePoint and Teams, which would break legitimate business flows and is not the targeted restriction the security team requires.

65
MCQeasy

A hospital uses Power Apps to manage patient intake forms. The app stores data in Microsoft Dataverse. The security policy requires that patient health information (PHI) be encrypted at rest and in transit. The environment is already configured with default Dataverse settings. The IT admin needs to ensure compliance. What should the admin do?

A.Enable customer-managed encryption keys for Dataverse.
B.No further action is needed; Dataverse encrypts data at rest and in transit by default.
C.Configure a VPN for all access to the environment.
D.Use Power Automate to encrypt data before storing it in Dataverse.
AnswerB

Microsoft Dataverse encrypts data at rest using transparent data encryption and secures data in transit with TLS by default, so the existing environment already satisfies the PHI encryption policy. No additional configuration is required to meet the stated compliance requirement.

Why this answer

Microsoft Dataverse encrypts all data at rest using SQL Server Transparent Data Encryption (TDE) and AES-256, and encrypts data in transit using TLS 1.2 or higher by default. Because the environment already uses default Dataverse settings, the encryption-at-rest and in-transit requirements for PHI are already satisfied without any additional configuration. Customer-managed keys are an optional compliance enhancement, not a baseline requirement.

Exam trap

PL-900 often tests the misconception that encryption must be manually enabled in Power Platform services, when in fact Dataverse encrypts data at rest and in transit by default.

How to eliminate wrong answers

Option A is wrong because customer-managed encryption keys (CMK) are an optional feature for organizations that require control over the key lifecycle for regulatory reasons — they are not needed to achieve encryption at rest, which is already on by default. Option C is wrong because a VPN secures network access paths but does not provide encryption at rest, and Dataverse traffic is already TLS-encrypted. Option D is wrong because Power Automate cannot encrypt data before it is stored in Dataverse in a way that satisfies at-rest encryption — Dataverse already handles encryption transparently at the storage layer.

66
MCQeasy

A Power Platform administrator needs to provide a team of makers with a shared environment that includes a pre-installed Microsoft Dataverse database and sample apps. The environment should be available to all team members without requiring them to create their own. What should the administrator do?

A.Instruct each team member to create their own personal environment and then share their apps with the team.
B.Use the default environment and enable the 'Sample apps' feature in the Power Platform admin center.
C.Create a Microsoft 365 group and enable Power Apps for the group, which automatically provisions a Dataverse database.
D.Create a new environment in the Power Platform admin center, select 'Yes' for 'Create a database for this environment?', and then assign the 'Environment Maker' security role to the team members.
AnswerD

Creating a new environment with a Dataverse database provides the shared data storage and sample apps. Assigning the Environment Maker security role grants the team members the ability to create apps, flows, and other resources within that environment. This approach directly satisfies the requirement for a shared environment with a database and maker access.

Why this answer

A shared environment with a Dataverse database is created explicitly in the Power Platform admin center by selecting the option to create a database. Assigning the Environment Maker role to team members grants them the necessary permissions to build resources in that environment. Personal environments and the default environment are not suitable for controlled team collaboration with a dedicated database.

Exam trap

The trap here is thinking that personal environments or the default environment can serve as a shared team environment with a Dataverse database, when a dedicated environment must be provisioned explicitly.

67
MCQhard

An organization has multiple Power Platform environments. The security team mandates that all environments must use Microsoft Entra ID conditional access policies to enforce multi-factor authentication. However, one environment hosts a service account that cannot perform interactive logins. What should the administrator do to comply without breaking the service account?

A.Create a new environment for the service account
B.Change the service account to use interactive login
C.Exclude the service account from the conditional access policy
D.Disable MFA for that environment
AnswerC

Conditional access applies only to interactive sign-ins, so a non-interactive service account cannot satisfy MFA prompts. Excluding it from the policy preserves the account's workload authentication while the remaining environments stay compliant with the security team's mandate.

Why this answer

Conditional Access policies in Microsoft Entra ID support targeted exclusions for specific users, groups, or service principals. Excluding the non-interactive service account from the MFA-requiring policy allows it to authenticate programmatically (e.g., via client credentials or service principal) without triggering an interactive MFA challenge, while all other users remain protected. This is the standard, supported approach for service accounts that cannot perform interactive logins.

Exam trap

The trap is thinking MFA can be configured 'inside' a Power Platform environment or that isolating the service account in a new environment bypasses tenant-level Conditional Access — CA is enforced at the Entra ID identity layer and applies tenant-wide.

How to eliminate wrong answers

Option A is wrong because creating a new environment does not exempt the service account from tenant-wide Conditional Access policies — CA applies at the identity layer, not per environment. Option B is wrong because service accounts are by design non-interactive; forcing interactive login breaks automation and violates the principle of least disruption. Option D is wrong because disabling MFA for an entire environment is overly broad, removes protection for all users in that environment, and is not how CA policies are scoped (they target identities, not environments).

68
MCQmedium

Your organization uses Power Automate to automate business processes. A flow that runs daily fails intermittently with 'HTTP 429 - Too Many Requests' errors. What should you do to resolve this issue?

A.Increase the frequency of the flow to run more often.
B.Change the flow trigger from a schedule to an instant trigger.
C.Set up an on-premises data gateway to bypass the throttling limits.
D.Configure retry policies with exponential backoff in the flow actions.
AnswerD

Exponential backoff retry policies directly address HTTP 429 throttling by spacing repeated attempts progressively further apart, letting the service's request limit reset before the next call. This satisfies the intermittent daily-flow failure constraint, since transient rate limiting resolves without manual intervention or flow redesign.

Why this answer

HTTP 429 responses indicate the flow is hitting Power Automate's service protection limits (throttling). The correct mitigation is to configure retry policies with exponential backoff on the actions that call the throttled connector, so the flow retries after increasing delays instead of failing immediately. This aligns with Microsoft's documented guidance for handling 429 errors.

Exam trap

PL-900 often tests the misconception that throttling can be bypassed by changing triggers or using gateways, when the correct answer is always to respect the limits and implement retry/backoff logic.

How to eliminate wrong answers

Option A is wrong because increasing the flow frequency would generate more requests and worsen throttling. Option B is wrong because changing the trigger type does not reduce the number of API calls or bypass throttling limits. Option C is wrong because an on-premises data gateway is for accessing on-premises data sources and does not bypass Power Platform service protection limits, which are enforced in the cloud.

69
MCQeasy

A company uses Power Automate flows that access Microsoft SharePoint and Microsoft Dataverse. They want to prevent data from leaving the organization. What should they configure?

A.Configure Microsoft Purview to automatically classify and protect data in Power Automate.
B.Enable Microsoft Defender XDR to monitor for suspicious data transfers.
C.Create a data loss prevention (DLP) policy in the Power Platform admin center that blocks sharing data with external connectors.
D.Apply Microsoft Entra ID Conditional Access policies to require managed devices.
AnswerC

A tenant-level DLP policy in the Power Platform admin center classifies connectors into business, non-business and blocked groups, preventing flows from combining SharePoint and Dataverse data with external connectors, which directly enforces the no-data-leaving constraint.

Why this answer

Data Loss Prevention (DLP) policies in the Power Platform admin center are specifically designed to prevent data from leaving the organization by controlling which connectors can share data. By blocking external connectors, the policy ensures that SharePoint and Dataverse data cannot be sent to unauthorized external services, directly addressing the requirement.

Exam trap

The trap here is that candidates often confuse data loss prevention with broader security tools like Microsoft Purview or Conditional Access, not realizing that DLP policies are the specific Power Platform feature for controlling connector-level data flow.

How to eliminate wrong answers

Option A is wrong because Microsoft Purview focuses on data classification and protection (e.g., labeling and encryption) but does not block data transfers between connectors in Power Automate flows. Option B is wrong because Microsoft Defender XDR is a threat detection and response tool for monitoring security incidents, not a mechanism to prevent data exfiltration via Power Automate connectors. Option D is wrong because Microsoft Entra ID Conditional Access policies control access based on device compliance or location, but they do not restrict how data flows between connectors within Power Automate.

70
MCQhard

An organization has multiple Power Platform environments including production, development, and test. They want to ensure that changes made in development are promoted to test and then to production, with approval gates. Which feature should they use?

A.Use Power Apps check-in feature and version history.
B.Use unmanaged solutions and export/import manually between environments.
C.Use managed solutions with environment variables and configure deployment pipelines.
D.Export solutions to a SharePoint document library and import from there.
AnswerC

Managed solutions package components with environment variables for environment-specific values, and Power Platform deployment pipelines promote them through development, test and production with configurable approval gates. This satisfies the requirement for staged promotion with approvals across multiple environments.

Why this answer

Managed solutions with environment variables and deployment pipelines provide a structured, automated way to promote solutions across environments with approval gates. This approach ensures that only managed solutions (which are locked and not directly editable) are deployed to production, while environment variables allow configuration values to change per environment without modifying the solution itself.

Exam trap

The trap here is that candidates often confuse manual export/import (Option B) as sufficient for controlled promotion, missing that managed solutions and deployment pipelines are required for approval gates and environment-specific configuration.

How to eliminate wrong answers

Option A is wrong because Power Apps check-in and version history are source control features for individual app versions, not for promoting full solutions across environments with approval gates. Option B is wrong because unmanaged solutions can be edited in any environment, making them unsuitable for controlled promotion, and manual export/import lacks approval gates and automation. Option D is wrong because exporting to a SharePoint document library is a storage method, not a deployment pipeline; it does not provide approval gates, environment variable management, or automated promotion.

71
Multi-Selectmedium

Which TWO actions can a Power Platform administrator perform in the Power Platform admin center?

Select 2 answers
A.Manage SharePoint Online site collections
B.Manage Exchange Online mailboxes
C.Create and delete environments
D.Create data loss prevention policies
E.Manage Microsoft Entra ID roles
AnswersC, D

This is a core function of the Power Platform admin center.

Why this answer

The Power Platform admin center provides administrators with the ability to create and delete environments, which are isolated containers for managing apps, flows, and data. This is a core administrative function that directly controls the lifecycle of Power Platform resources.

Exam trap

The trap here is that candidates may confuse the Power Platform admin center with the broader Microsoft 365 admin center, assuming it can manage all Microsoft 365 workloads like SharePoint and Exchange, when in reality it is scoped to Power Platform-specific tasks such as environment management and DLP policies.

72
MCQeasy

A Power Platform administrator wants to see the capacity usage of all environments in the tenant. Where should they look?

A.Power Platform admin center > Environments
B.Power Platform admin center > Capacity
C.Power Platform admin center > Analytics
D.Power Platform admin center > Billing
AnswerB

Tenant-wide storage, database, file and add-on consumption across every environment is aggregated in the Power Platform admin center's Capacity page, which reports entitlement versus actual usage per environment. Individual environment settings and the maker portal show only scoped or per-app detail.

Why this answer

The Capacity page in the Power Platform admin center provides a tenant-level view of all capacity entitlements (database, file, log) and their consumption across environments. This is the dedicated location for monitoring capacity usage, including add-ons and storage overages, as documented in Microsoft's capacity management guidance.

Exam trap

The trap here is that candidates confuse the Environments list (where you manage individual environment settings) with the Capacity page (which is the sole location for tenant-wide storage monitoring), leading them to select the more familiar Environments option.

How to eliminate wrong answers

Option A is wrong because the Environments page lists individual environments and their details but does not aggregate capacity usage across the tenant. Option C is wrong because Analytics provides usage and adoption metrics (e.g., active users, API calls) rather than raw capacity consumption. Option D is wrong because Billing handles subscription, licensing, and invoice information, not the technical capacity allocation or usage tracking.

73
Multi-Selecteasy

Which TWO are best practices for managing Power Platform environments in a large enterprise?

Select 2 answers
A.Give all users the ability to create environments
B.Assign the System Administrator role to all users
C.Use a single environment for all apps
D.Use separate environments for development, test, and production
E.Apply DLP policies to control data flow between connectors
AnswersD, E

Separate development, test, and production environments isolate unmanaged customisations from live business data, satisfying the stem's large-enterprise constraint of controlled release governance. Changes are validated in test before promotion, preventing faulty solutions from disrupting production apps and flows, and aligning with Microsoft Entra ID-governed environment security boundaries.

Why this answer

Option D is correct because separating development, test, and production environments is a core ALM best practice in Power Platform, allowing makers to build and validate solutions in isolation before promoting them to production, thereby preventing untested changes from affecting live business apps. Option E is correct because Data Loss Prevention (DLP) policies define connector groups (Business, Non-Business, Blocked) and govern which connectors can share data, which is essential in a large enterprise to prevent sensitive data from flowing into unauthorized services. The unmarked options do not belong: A is wrong because allowing every user to create environments leads to environment sprawl and ungoverned resources, B is wrong because granting System Administrator to all users violates least privilege and exposes the tenant to misconfiguration, and C is wrong because a single shared environment mixes development and production workloads, making change management and security impossible.

Exam trap

PL-900 often tests governance fundamentals, and candidates may pick options that sound convenient (like letting everyone create environments) without recognizing that they undermine security and manageability — the trap is confusing ease of use with best practice.

74
MCQhard

Your organization has a Power Apps portal that allows external users to submit support tickets. You need to ensure that only authenticated external users from specific domains can access the portal. What should you configure?

A.Create a data loss prevention (DLP) policy that blocks external users.
B.Restrict access to the portal by IP address using a web application firewall.
C.Share the portal URL only with users from the allowed domains.
D.Configure the portal to use Microsoft Entra ID authentication and set up domain restrictions.
AnswerD

Microsoft Entra ID authentication with domain restrictions enforces tenant-based sign-in, so only users from the specified domains authenticate. This satisfies the requirement that external users be authenticated and limited to particular domains, which anonymous or local portal accounts cannot enforce.

Why this answer

Power Apps portals can be configured to use Microsoft Entra ID (formerly Azure AD) as the identity provider, and within the portal settings you can restrict sign-in to users from specific domains. This ensures that only authenticated external users whose email domain matches the allowed list can access the portal, meeting the requirement without relying on IP filtering or obscurity.

Exam trap

The trap here is that candidates often confuse DLP policies (which control data connectors) with access control mechanisms, or they mistakenly believe that simply sharing a URL (security by obscurity) or using IP restrictions (which don't authenticate users) can satisfy domain-based authentication requirements.

How to eliminate wrong answers

Option A is wrong because a Data Loss Prevention (DLP) policy controls which connectors can be used in Power Apps and Power Automate flows, not who can access a portal; it cannot block external users from accessing the portal itself. Option B is wrong because restricting by IP address using a web application firewall (WAF) would block or allow traffic based on network location, not on user authentication or domain membership, and external users may have dynamic IPs. Option C is wrong because sharing the portal URL only with allowed domains relies on security through obscurity and does not enforce authentication; anyone who obtains the URL can access the portal unless additional authentication and domain restrictions are configured.

75
MCQmedium

A company has a production environment containing a model-driven app used by 400 sales staff. The administrator wants to review who accessed the app in the last 30 days and which users were inactive, without enabling any paid auditing features. Which tool should the administrator use?

A.Microsoft Purview audit log search filtered to the Dataverse workload
B.The Power Platform admin center Analytics section for the environment, selecting the Power Apps report
C.Environment-level data loss prevention policy reports in the Power Platform admin center
D.The Microsoft 365 admin center Reports dashboard, Service usage section
AnswerB

The Analytics area in the Power Platform admin center provides ready-made usage reports per environment, including which apps were opened, by how many users, and which users were inactive, with no paid add-on required. It directly answers the access and inactivity question for the production environment.

Why this answer

Environment analytics in the Power Platform admin center is the built-in, no-extra-cost way to see app usage and inactive users for a specific environment. It reports which apps are used, how often, and by whom, so the administrator can identify inactive sales staff without enabling paid auditing or digging through compliance tooling.

Exam trap

The trap here is assuming that audit logging tools are needed to see who used an app, when usage analytics in the admin center already surface that information.

Page 1 of 2 · 95 questions totalNext →

Ready to test yourself?

Try a timed practice session using only Manage the Microsoft Power Platform environment questions.