Two Core Actions: Assign Security Roles and Create/Delete Environments
Which TWO actions can an administrator perform in the Power Platform admin center to manage environments?
Quick Answer
The Power Platform admin center gives administrators two distinct layers of control over environments: managing who can do what inside an environment, and managing the environments themselves as containers. Assigning security roles falls into the first layer, since it controls which users can access apps, flows, and data within a given environment, which is a core identity and access management task administrators handle regularly. Creating and deleting environments falls into the second layer, since it's the lifecycle management capability that lets administrators provision new isolated workspaces for development, testing, or production, and remove them when they're no longer needed. These two actions are correct together because they represent genuinely different administrative responsibilities rather than two versions of the same task, which is a common pattern in 'choose two' exam questions: the correct pair usually spans two separate categories of capability rather than two overlapping ones. When you see a question asking which actions an administrator can perform in the admin center, separate the options mentally into access and permissions within an environment versus the environment as a whole (its creation, deletion, backup, or copy), and look for one clearly correct action in each category rather than assuming both correct answers come from the same bucket.
⚠ Common exam trap
Watch out — candidates often confuse the Power Platform admin center with other Microsoft 365 admin centers, mistakenly thinking tasks like SharePoint permissions or Power BI capacity management are handled within the same interface.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign security roles to users within an environment.
The Power Platform admin center allows administrators to assign security roles to users within an environment, controlling their access to resources like apps, flows, and data. This is a core administrative task for managing environment-level permissions. Option C is correct because creating and deleting environments is a fundamental capability of the Power Platform admin center, enabling administrators to provision and remove isolated workspaces for development, testing, or production.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Assign security roles to users within an environment.
Why this is correct
Security roles are managed per environment in the Power Platform admin center.
- ✗
Configure SharePoint site permissions.
Why it's wrong here
SharePoint site permissions are managed in the SharePoint admin center.
- ✓
Create and delete environments.
Why this is correct
Environment lifecycle management is a core function of the Power Platform admin center.
- ✗
Manage Power BI Premium capacity.
Why it's wrong here
Power BI capacity is managed in the Power BI admin center.
- ✗
Configure Microsoft Entra ID Conditional Access policies.
Why it's wrong here
Conditional Access is managed in the Azure portal, not Power Platform admin center.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 904 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on PL-900
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. Which TWO actions can a Power Platform admin perform in the Power Platform admin center to manage environments? (Choose two.)
medium- A.Modify Dataverse table schemas.
- ✓ B.Create and delete environments.
- ✓ C.Manage environment security roles.
- D.Assign Power Apps licenses to users.
- E.Create Microsoft Entra ID security groups.
Why B: Options B and C are correct. A Power Platform admin can create and delete environments and manage environment security roles in the Power Platform admin center. Option A is incorrect because modifying Dataverse table schemas is done in the Power Apps maker portal, not the admin center. Option D is incorrect because assigning Power Apps licenses to users is performed in the Microsoft 365 admin center. Option E is incorrect because creating Microsoft Entra ID security groups is done in the Microsoft Entra admin center.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.