Courseiva

PL-900 Practice Question: Manage the Microsoft Power Platform environment

Your organization uses Power Virtual Agents (now Copilot Studio) for customer service. You need to ensure that the bot can access customer data from a Dataverse table that contains sensitive information. What is the best approach to secure the data?

⚠ Common exam trap

It's easy for candidates to confuse DLP policies (which govern connector usage) with data access control, or they assume user authentication methods like MFA apply to non-interactive service principals, leading them to pick options A or B instead of understanding the service principal security role mechanism.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Assign appropriate security roles and field-level security to the bot's service principal.

Power Virtual Agents (Copilot Studio) uses a service principal to authenticate with Dataverse. By assigning appropriate security roles and field-level security to that service principal, you can grant the bot granular, least-privilege access to only the necessary customer data, ensuring sensitive information is protected while still enabling the bot to function.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a data loss prevention (DLP) policy to block the bot from accessing the table.

    Why it's wrong here

    Blocking the table outright prevents the bot from reading the customer data it needs, so the requirement fails. DLP policies govern connector and action classification across Power Platform environments, restricting which services may coexist in a flow or app. That suits compliance boundaries, not granting a bot scoped access to a sensitive Dataverse table.

  • ✗

    Use the bot's authentication settings to require multi-factor authentication.

    Why it's wrong here

    Authentication settings control user identity, not data access.

  • ✓

    Assign appropriate security roles and field-level security to the bot's service principal.

    Why this is correct

    Dataverse enforces access through security roles, and field-level security masks sensitive columns even for privileged identities. Granting the bot's service principal a least-privilege role with field-level security restricts it to only the customer data required.

  • ✗

    Restrict access to the environment to only the bot's service account.

    Why it's wrong here

    Environment-level restriction limits who can administer or open the environment; it does not filter which Dataverse rows the bot retrieves at runtime, so the bot still reads sensitive records. It is tempting because locking down an environment is a real hardening step, and that would be correct for preventing unauthorised makers from editing the bot.

About these practice questions

Courseiva writes every PL-900 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This PL-900 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PL-900 exam.