Courseiva

PL-900 Demonstrate the capabilities of Power Apps Practice Question

Exhibit

Refer to the exhibit.

{
  "policies": [
    {
      "name": "BlockScreenCapture",
      "description": "Prevent screen capture in Power Apps mobile app",
      "settings": {
        "screenCaptureEnabled": false
      }
    }
  ]
}

Refer to the exhibit. An administrator wants to enforce a mobile app management policy that prevents screen capture in Power Apps. Which Microsoft service should the administrator use to deploy this policy?

⚠ Common exam trap

PL-900 often tests the confusion between Intune (device/app management) and Purview (data compliance) — candidates pick Purview for anything involving 'policy' or 'protection' even when the control is a mobile app runtime restriction.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Microsoft Intune

Microsoft Intune is the mobile device and application management (MDM/MAM) service in the Microsoft 365 stack, and it is where app protection policies are configured. An Intune app protection policy can enforce data-loss-prevention controls such as blocking screen capture, preventing copy/paste to unmanaged apps, and requiring a PIN, specifically for mobile apps like Power Apps on iOS and Android. This is the correct service to deploy the policy described.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Microsoft Entra ID

    Why it's wrong here

    Microsoft Entra ID handles identity, authentication and conditional access; it cannot apply app-level policies such as blocking screen capture. It is correct for controlling sign-in, MFA and device compliance, whereas Intune app protection policies govern app data behaviour.

  • ✗

    Microsoft Defender XDR

    Why it's wrong here

    Defender XDR handles threat detection, hunting and response across endpoints, identities and email; it cannot deploy app protection policies. It is tempting because it governs device and identity security, and would be the choice for investigating or blocking malicious activity, not for restricting screen capture inside Power Apps on mobile.

  • ✓

    Microsoft Intune

    Why this is correct

    Microsoft Intune app protection policies enforce mobile app management restrictions such as blocking screen capture on enrolled or unenrolled devices. Power Apps platform settings and Dataverse security roles govern data access, not device-level app behaviour, so Intune is required here.

  • ✗

    Microsoft Purview

    Why it's wrong here

    Microsoft Purview covers data classification, sensitivity labels, DLP and compliance auditing, not mobile app management. It is tempting because it governs data protection across Microsoft 365, and would be correct for labelling or preventing sharing of sensitive content, but screen-capture blocking on mobile requires Intune app protection policies.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.