Courseiva

PL-900 Practice Question: Demonstrate the capabilities of Power Automate

Your organization uses Power Automate to automate onboarding processes. The flow creates a user in Microsoft Entra ID, assigns licenses, and sends a welcome email. Recently, the flow failed because the 'Create user' action returned 'PrivilegedOperationNotAllowed'. What is the most likely cause?

⚠ Common exam trap

The trap is confusing authorization errors with other failure modes — candidates often pick 'user already exists' or 'rate limits' because those are common flow failures, but 'PrivilegedOperationNotAllowed' is a specific Microsoft Graph permissions error that points to missing Entra ID roles or Graph scopes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The service principal lacks required permissions in Microsoft Entra ID

The error 'PrivilegedOperationNotAllowed' from the 'Create user' action in Power Automate indicates that the connection or service principal used by the flow lacks the required Microsoft Graph permissions (such as User.ReadWrite.All or Directory.ReadWrite.All) in Microsoft Entra ID. This is a permissions issue, not a data or rate-limit issue. The service principal must be granted admin consent for the necessary Graph scopes.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The user already exists in the directory

    Why it's wrong here

    A duplicate user returns a 409 conflict error, not PrivilegedOperationNotAllowed. That code signals the connection's service principal lacks the User.ReadWrite.All Graph permission or an admin role, so Microsoft Entra ID rejects the write. Duplicate detection matters when importing bulk users, where conflicts are expected and handled.

  • ✗

    The flow is using an expired connection

    Why it's wrong here

    PrivilegedOperationNotAllowed signals the connection's account lacks the Microsoft Entra ID directory role required to create users, such as User Administrator. An expired connection produces authentication failures instead. It tempts because connection expiry is a frequent Power Automate fault, but it cannot yield a privileged-operation authorisation error.

  • ✓

    The service principal lacks required permissions in Microsoft Entra ID

    Why this is correct

    PrivilegedOperationNotAllowed indicates the connection's service principal lacks the Microsoft Entra ID permission required by the Create user action, such as User.ReadWrite.All with admin consent granted. Insufficient Graph API authorisation causes the directory write to be rejected.

  • ✗

    The flow has exceeded API rate limits

    Why it's wrong here

    Rate limiting returns HTTP 429 throttling responses, not 'PrivilegedOperationNotAllowed', which signals the connection lacks the directory role or permission required for user creation. Rate limits are tempting because they do cause intermittent flow failures, and would be correct if the flow were issuing too many calls per interval.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.