MB-800 · Question #240
Drag and Drop Question A company uses Business Central and plans to automate its processes by using Power Automate. The company finance manager wants to restrict access to Power Automate features…
The correct answer is As an administrator, agree to the integration notice on the Privacy Notices Status page on behalf of all users or allow users to decide themselves.; Add the system permission Allow Action Automate (ID 9630) to the assigned permissions sets.; Validate that authorized users have the Automate Action permission. Business Central + Power Automate: Access Control Setup The Goal Restrict instant flow creation/execution to only trained users. This requires three sequential steps: enabling the integration, granting permissions, then verifying access. --- Step-by-Step Breakdown Step 1: Agree…
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- As an administrator, agree to the integration notice on the Privacy Notices Status page on behalf of all users or allow users to decide themselves.
- Add the system permission Allow Action Automate (ID 9630) to the assigned permissions sets.
- Validate that authorized users have the Automate Action permission.
Explanation
Business Central + Power Automate: Access Control Setup
The Goal
Restrict instant flow creation/execution to only trained users. This requires three sequential steps: enabling the integration, granting permissions, then verifying access.
Step-by-Step Breakdown
Step 1: Agree to the integration notice (Privacy Notices Status page)
This is the prerequisite gate. Before any user can interact with Power Automate from Business Central, the integration must be legally acknowledged - Microsoft requires admin consent due to data sharing between services. Without this step, the Automate menu/actions are simply not available to anyone, regardless of permissions. The admin either accepts on behalf of all users or delegates that decision to each user individually.
Why first: You cannot configure what doesn't exist. The integration must be active before permission controls have anything to act on.
Step 2: Add system permission Allow Action Automate (ID 9630) to the assigned permission sets
Once the integration is live, access is controlled by a specific system permission (9630). By default, the Automate action may be visible but not functional for restricted users. Adding this permission to only the relevant permission sets (those assigned to trained users) scopes access appropriately.
Why second: You first need the integration on (Step 1), then you configure who gets access via the permission set.
Step 3: Validate that authorized users have the Automate Action permission
After configuration, verification confirms the setup is correct - checking that trained users actually have the permission applied via their assigned permission sets.
Why third: Validation is always the final step; you confirm the configuration works as intended before declaring it done.
Why the Wrong Items Are Excluded
| Item | Why Wrong |
|---|---|
| Disagree to the integration notice | This would disable the feature entirely for all users - the opposite of the goal |
| Remove permission ID 9630 | This restricts access, but the question asks you to grant it to trained users, not remove it |
Common Mistakes
- Skipping Step 1: Candidates sometimes jump straight to permissions, forgetting that the integration consent is a hard prerequisite - no consent means no Automate action appears at all.
- Confusing remove vs. add: The scenario is about enabling trained users, not locking out others. The removal option is a distractor that sounds like "restricting access" but would remove it from everyone.
- Validation last: Some candidates place validation second, before permissions are fully applied. Always configure first, validate after.
Topics
Community Discussion
No community discussion yet for this question.
