PL-900 Practice Question: Demonstrate the capabilities of Power Automate
Your organization uses Power Automate to automate onboarding processes. The flow creates a user in Microsoft Entra ID, assigns licenses, and sends a welcome email. Recently, the flow failed because the 'Create user' action returned 'PrivilegedOperationNotAllowed'. What is the most likely cause?
⚠ Common exam trap
The trap is confusing authorization errors with other failure modes — candidates often pick 'user already exists' or 'rate limits' because those are common flow failures, but 'PrivilegedOperationNotAllowed' is a specific Microsoft Graph permissions error that points to missing Entra ID roles or Graph scopes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
The service principal lacks required permissions in Microsoft Entra ID
The error 'PrivilegedOperationNotAllowed' from the 'Create user' action in Power Automate indicates that the connection or service principal used by the flow lacks the required Microsoft Graph permissions (such as User.ReadWrite.All or Directory.ReadWrite.All) in Microsoft Entra ID. This is a permissions issue, not a data or rate-limit issue. The service principal must be granted admin consent for the necessary Graph scopes.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The user already exists in the directory
Why it's wrong here
A duplicate user returns a 409 conflict error, not PrivilegedOperationNotAllowed. That code signals the connection's service principal lacks the User.ReadWrite.All Graph permission or an admin role, so Microsoft Entra ID rejects the write. Duplicate detection matters when importing bulk users, where conflicts are expected and handled.
- ✗
The flow is using an expired connection
Why it's wrong here
PrivilegedOperationNotAllowed signals the connection's account lacks the Microsoft Entra ID directory role required to create users, such as User Administrator. An expired connection produces authentication failures instead. It tempts because connection expiry is a frequent Power Automate fault, but it cannot yield a privileged-operation authorisation error.
- ✓
The service principal lacks required permissions in Microsoft Entra ID
Why this is correct
PrivilegedOperationNotAllowed indicates the connection's service principal lacks the Microsoft Entra ID permission required by the Create user action, such as User.ReadWrite.All with admin consent granted. Insufficient Graph API authorisation causes the directory write to be rejected.
- ✗
The flow has exceeded API rate limits
Why it's wrong here
Rate limiting returns HTTP 429 throttling responses, not 'PrivilegedOperationNotAllowed', which signals the connection lacks the directory role or permission required for user creation. Rate limits are tempting because they do cause intermittent flow failures, and would be correct if the flow were issuing too many calls per interval.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.