Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

Which TWO are best practices for managing Power Platform environments in a large enterprise?

⚠ Common exam trap

PL-900 often tests governance fundamentals, and candidates may pick options that sound convenient (like letting everyone create environments) without recognizing that they undermine security and manageability — the trap is confusing ease of use with best practice.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Use separate environments for development, test, and production

Option D is correct because separating development, test, and production environments is a core ALM best practice in Power Platform, allowing makers to build and validate solutions in isolation before promoting them to production, thereby preventing untested changes from affecting live business apps. Option E is correct because Data Loss Prevention (DLP) policies define connector groups (Business, Non-Business, Blocked) and govern which connectors can share data, which is essential in a large enterprise to prevent sensitive data from flowing into unauthorized services. The unmarked options do not belong: A is wrong because allowing every user to create environments leads to environment sprawl and ungoverned resources, B is wrong because granting System Administrator to all users violates least privilege and exposes the tenant to misconfiguration, and C is wrong because a single shared environment mixes development and production workloads, making change management and security impossible.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Give all users the ability to create environments

    Why it's wrong here

    Unrestricted environment creation scatters governance across the tenant, defeating centralised administration and DLP policy enforcement. It is tempting because self-service environments suit small teams prototyping quickly, where maker autonomy outweighs control; at enterprise scale, creation should be restricted to admins or a governed request process.

  • ✗

    Assign the System Administrator role to all users

    Why it's wrong here

    Granting System Administrator to everyone removes least-privilege separation, letting any maker alter security settings and environments tenant-wide. The temptation is convenience, since broad rights avoid access requests, but the correct practise is scoped security roles such as Environment Maker assigned to defined groups.

  • ✗

    Use a single environment for all apps

    Why it's wrong here

    A single environment mixes development, test and production, so a faulty app or flow can disrupt every business solution at once. The temptation is simplified administration, but enterprise governance requires separate environments per workload or lifecycle stage, with managed solutions promoted between them.

  • ✓

    Use separate environments for development, test, and production

    Why this is correct

    Separate development, test, and production environments isolate unmanaged customisations from live business data, satisfying the stem's large-enterprise constraint of controlled release governance. Changes are validated in test before promotion, preventing faulty solutions from disrupting production apps and flows, and aligning with Microsoft Entra ID-governed environment security boundaries.

  • ✓

    Apply DLP policies to control data flow between connectors

    Why this is correct

    Data loss prevention policies define connector classification (Business, Non-Business, Blocked), restricting cross-connector data flow within an environment. This directly satisfies the enterprise governance requirement by preventing users from combining connectors that would leak corporate data into unmanaged services.

About these practice questions

One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.