PL-900 Demonstrate the capabilities of Power Apps Practice Question
Exhibit
Refer to the exhibit.
{
"policies": [
{
"name": "BlockScreenCapture",
"description": "Prevent screen capture in Power Apps mobile app",
"settings": {
"screenCaptureEnabled": false
}
}
]
}Refer to the exhibit. An administrator wants to enforce a mobile app management policy that prevents screen capture in Power Apps. Which Microsoft service should the administrator use to deploy this policy?
⚠ Common exam trap
PL-900 often tests the confusion between Intune (device/app management) and Purview (data compliance) — candidates pick Purview for anything involving 'policy' or 'protection' even when the control is a mobile app runtime restriction.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Intune
Microsoft Intune is the mobile device and application management (MDM/MAM) service in the Microsoft 365 stack, and it is where app protection policies are configured. An Intune app protection policy can enforce data-loss-prevention controls such as blocking screen capture, preventing copy/paste to unmanaged apps, and requiring a PIN, specifically for mobile apps like Power Apps on iOS and Android. This is the correct service to deploy the policy described.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Microsoft Entra ID
Why it's wrong here
Microsoft Entra ID handles identity, authentication and conditional access; it cannot apply app-level policies such as blocking screen capture. It is correct for controlling sign-in, MFA and device compliance, whereas Intune app protection policies govern app data behaviour.
- ✗
Microsoft Defender XDR
Why it's wrong here
Defender XDR handles threat detection, hunting and response across endpoints, identities and email; it cannot deploy app protection policies. It is tempting because it governs device and identity security, and would be the choice for investigating or blocking malicious activity, not for restricting screen capture inside Power Apps on mobile.
- ✓
Microsoft Intune
Why this is correct
Microsoft Intune app protection policies enforce mobile app management restrictions such as blocking screen capture on enrolled or unenrolled devices. Power Apps platform settings and Dataverse security roles govern data access, not device-level app behaviour, so Intune is required here.
- ✗
Microsoft Purview
Why it's wrong here
Microsoft Purview covers data classification, sensitivity labels, DLP and compliance auditing, not mobile app management. It is tempting because it governs data protection across Microsoft 365, and would be correct for labelling or preventing sharing of sensitive content, but screen-capture blocking on mobile requires Intune app protection policies.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.