PL-100 · Question #292
Drag and Drop Question A company uses Power Apps and Microsoft Dataverse. The company has model-driven apps across multiple Microsoft Dataverse environments in the same tenant. You must grant…
The correct answer is Microsoft Power Platform Administrator; System Customizer. This question assesses the understanding of Microsoft Power Platform security roles and the principle of least privilege for granting Power Apps makers different levels of access for sharing model-driven apps across Dataverse environments.
Question
Exhibit
Answer Area
Drag items
Correct arrangement
- Microsoft Power Platform Administrator
- System Customizer
Explanation
This question assesses the understanding of Microsoft Power Platform security roles and the principle of least privilege for granting Power Apps makers different levels of access for sharing model-driven apps across Dataverse environments.
Approach. To correctly answer this question, the test-taker must drag the appropriate security role to each requirement based on the principle of least privilege.
-
Requirement: Share in all Microsoft Dataverse environments.
- Correct Security Role: Microsoft Power Platform Administrator.
- Reasoning: The 'Microsoft Power Platform Administrator' role is a tenant-level role that grants full administrative control over all Power Platform environments and resources across the entire tenant. This is the only role among the options that provides the necessary privileges to manage and share model-driven apps across 'all Microsoft Dataverse environments' within the tenant.
-
Requirement: Share in one environment and view only table records they create.
- Correct Security Role: System Customizer.
- Reasoning: The 'System Customizer' role is an environment-specific role that allows a user to customize the system within a single Dataverse environment. This includes capabilities to create, modify, and publish solution components, including model-driven apps, and to share those apps within that environment. While the default 'System Customizer' role typically grants broader data access (often Organization-level read privileges for many entities, which seemingly contradicts 'view only table records they create'), its primary function as a maker role for managing and sharing apps within one environment is crucial. The 'Environment Maker' role allows creating their own apps and sharing their own apps, but 'System Customizer' offers broader app management and sharing capabilities within an environment (not just personal creations). The data access restriction ('view only table records they create') would be achieved by applying additional, more granular security roles or specific table privileges in conjunction with the System Customizer role for overall app management and sharing within the specific environment, adhering to the principle of least privilege for the data aspect.
Common mistakes.
- common_mistake. 1. Using 'Environment Maker' for 'Share in all Microsoft Dataverse environments.': The 'Environment Maker' role is an environment-level role, limited to creating and sharing their own apps within a single environment. It does not provide the tenant-wide privileges required to share apps across all Dataverse environments.
- Using 'Microsoft Power Platform Administrator' for 'Share in one environment and view only table records they create.': This choice would violate the principle of least privilege. The 'Microsoft Power Platform Administrator' role is a tenant-level administrator and grants excessive privileges far beyond what is required to share an app within a single environment and view only self-created records.
- Using 'Environment Maker' for 'Share in one environment and view only table records they create.' (instead of System Customizer): While 'Environment Maker' allows creating and sharing their own apps within one environment, the requirement 'Share model-driven apps' (plural, potentially not just their own) within one environment aligns better with the broader app management and customization capabilities of the 'System Customizer' role. The 'System Customizer' can manage and publish more comprehensively within an environment, including sharing apps they have privileges for (even if not solely their own creations). The specific data access restriction for viewing only self-created records is a granular privilege that might be layered on top of the chosen app-management role, with 'System Customizer' providing the necessary environment-level app sharing capability.
Concept tested. Microsoft Dataverse and Power Platform security roles, environment management, tenant-level vs. environment-level privileges, and applying the principle of least privilege in Power Apps security contexts.
Topics
Community Discussion
No community discussion yet for this question.
