Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

Your organization has a Power Apps portal that allows external users to submit support tickets. You need to ensure that only authenticated external users from specific domains can access the portal. What should you configure?

⚠ Common exam trap

Test-takers frequently confuse DLP policies (which control data connectors) with access control mechanisms, or they mistakenly believe that simply sharing a URL (security by obscurity) or using IP restrictions (which don't authenticate users) can satisfy domain-based authentication requirements.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Configure the portal to use Microsoft Entra ID authentication and set up domain restrictions.

Power Apps portals can be configured to use Microsoft Entra ID (formerly Azure AD) as the identity provider, and within the portal settings you can restrict sign-in to users from specific domains. This ensures that only authenticated external users whose email domain matches the allowed list can access the portal, meeting the requirement without relying on IP filtering or obscurity.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Create a data loss prevention (DLP) policy that blocks external users.

    Why it's wrong here

    DLP policies govern connector and data-flow usage within Power Platform, not who may authenticate to a portal, so external users remain unaffected. It is tempting because DLP restricts data movement, and would be correct for preventing connectors from leaking data between environments.

  • ✗

    Restrict access to the portal by IP address using a web application firewall.

    Why it's wrong here

    An IP-based firewall restriction filters by network origin, not by authenticated identity or email domain, so users on any network could still reach the portal. It is tempting because firewalls control perimeter access, and would be correct for blocking known malicious ranges rather than verifying external user domains.

  • ✗

    Share the portal URL only with users from the allowed domains.

    Why it's wrong here

    Obscuring the URL provides no authentication or domain verification; anyone who obtains the link can access the portal. It is tempting because limiting distribution feels like access control, and would be correct for unlisted public content where secrecy, not identity, is the requirement.

  • ✓

    Configure the portal to use Microsoft Entra ID authentication and set up domain restrictions.

    Why this is correct

    Microsoft Entra ID authentication with domain restrictions enforces tenant-based sign-in, so only users from the specified domains authenticate. This satisfies the requirement that external users be authenticated and limited to particular domains, which anonymous or local portal accounts cannot enforce.

About these practice questions

One of 701 original PL-900 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.