PL-900 Practice Question: Manage the Microsoft Power Platform environment
Your organization uses Power Virtual Agents (now Copilot Studio) for customer service. You need to ensure that the bot can access customer data from a Dataverse table that contains sensitive information. What is the best approach to secure the data?
⚠ Common exam trap
It's easy for candidates to confuse DLP policies (which govern connector usage) with data access control, or they assume user authentication methods like MFA apply to non-interactive service principals, leading them to pick options A or B instead of understanding the service principal security role mechanism.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Assign appropriate security roles and field-level security to the bot's service principal.
Power Virtual Agents (Copilot Studio) uses a service principal to authenticate with Dataverse. By assigning appropriate security roles and field-level security to that service principal, you can grant the bot granular, least-privilege access to only the necessary customer data, ensuring sensitive information is protected while still enabling the bot to function.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Configure a data loss prevention (DLP) policy to block the bot from accessing the table.
Why it's wrong here
Blocking the table outright prevents the bot from reading the customer data it needs, so the requirement fails. DLP policies govern connector and action classification across Power Platform environments, restricting which services may coexist in a flow or app. That suits compliance boundaries, not granting a bot scoped access to a sensitive Dataverse table.
- ✗
Use the bot's authentication settings to require multi-factor authentication.
Why it's wrong here
Authentication settings control user identity, not data access.
- ✓
Assign appropriate security roles and field-level security to the bot's service principal.
Why this is correct
Dataverse enforces access through security roles, and field-level security masks sensitive columns even for privileged identities. Granting the bot's service principal a least-privilege role with field-level security restricts it to only the customer data required.
- ✗
Restrict access to the environment to only the bot's service account.
Why it's wrong here
Environment-level restriction limits who can administer or open the environment; it does not filter which Dataverse rows the bot retrieves at runtime, so the bot still reads sensitive records. It is tempting because locking down an environment is a real hardening step, and that would be correct for preventing unauthorised makers from editing the bot.
Go deeper
Related to this question
About these practice questions
Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.