nerdexam
Microsoft

PL-100 · Question #292

Drag and Drop Question A company uses Power Apps and Microsoft Dataverse. The company has model-driven apps across multiple Microsoft Dataverse environments in the same tenant. You must grant…

The correct answer is Microsoft Power Platform Administrator; System Customizer. This question assesses the understanding of Microsoft Power Platform security roles and the principle of least privilege for granting Power Apps makers different levels of access for sharing model-driven apps across Dataverse environments.

Create business solutions

Question

Drag and Drop Question A company uses Power Apps and Microsoft Dataverse. The company has model-driven apps across multiple Microsoft Dataverse environments in the same tenant. You must grant privileges to Power Apps makers to achieve the following: - Share model-driven apps in multiple Microsoft Dataverse environments. - Share model-driven apps in only one of the Microsoft Dataverse environments and view only table records that they create themselves. You need to share the model-driven app with users by using the principle of least privilege. Which security role privilege should you grant for each requirement? To answer, drag the appropriate security roles to the correct requirements. Each security role may be used once, more than once, or not at all. You may need to drag the split bar between panes or scroll to view content. NOTE: Each correct answer is worth one point. Answer:

Exhibit

PL-100 question #292 exhibit

Answer Area

Drag items

System CustomizerMicrosoft Power Platform AdministratorEnvironment Maker

Correct arrangement

  • Microsoft Power Platform Administrator
  • System Customizer

Explanation

This question assesses the understanding of Microsoft Power Platform security roles and the principle of least privilege for granting Power Apps makers different levels of access for sharing model-driven apps across Dataverse environments.

Approach. To correctly answer this question, the test-taker must drag the appropriate security role to each requirement based on the principle of least privilege.

  1. Requirement: Share in all Microsoft Dataverse environments.

    • Correct Security Role: Microsoft Power Platform Administrator.
    • Reasoning: The 'Microsoft Power Platform Administrator' role is a tenant-level role that grants full administrative control over all Power Platform environments and resources across the entire tenant. This is the only role among the options that provides the necessary privileges to manage and share model-driven apps across 'all Microsoft Dataverse environments' within the tenant.
  2. Requirement: Share in one environment and view only table records they create.

    • Correct Security Role: System Customizer.
    • Reasoning: The 'System Customizer' role is an environment-specific role that allows a user to customize the system within a single Dataverse environment. This includes capabilities to create, modify, and publish solution components, including model-driven apps, and to share those apps within that environment. While the default 'System Customizer' role typically grants broader data access (often Organization-level read privileges for many entities, which seemingly contradicts 'view only table records they create'), its primary function as a maker role for managing and sharing apps within one environment is crucial. The 'Environment Maker' role allows creating their own apps and sharing their own apps, but 'System Customizer' offers broader app management and sharing capabilities within an environment (not just personal creations). The data access restriction ('view only table records they create') would be achieved by applying additional, more granular security roles or specific table privileges in conjunction with the System Customizer role for overall app management and sharing within the specific environment, adhering to the principle of least privilege for the data aspect.

Common mistakes.

  • common_mistake. 1. Using 'Environment Maker' for 'Share in all Microsoft Dataverse environments.': The 'Environment Maker' role is an environment-level role, limited to creating and sharing their own apps within a single environment. It does not provide the tenant-wide privileges required to share apps across all Dataverse environments.
  1. Using 'Microsoft Power Platform Administrator' for 'Share in one environment and view only table records they create.': This choice would violate the principle of least privilege. The 'Microsoft Power Platform Administrator' role is a tenant-level administrator and grants excessive privileges far beyond what is required to share an app within a single environment and view only self-created records.
  2. Using 'Environment Maker' for 'Share in one environment and view only table records they create.' (instead of System Customizer): While 'Environment Maker' allows creating and sharing their own apps within one environment, the requirement 'Share model-driven apps' (plural, potentially not just their own) within one environment aligns better with the broader app management and customization capabilities of the 'System Customizer' role. The 'System Customizer' can manage and publish more comprehensively within an environment, including sharing apps they have privileges for (even if not solely their own creations). The specific data access restriction for viewing only self-created records is a granular privilege that might be layered on top of the chosen app-management role, with 'System Customizer' providing the necessary environment-level app sharing capability.

Concept tested. Microsoft Dataverse and Power Platform security roles, environment management, tenant-level vs. environment-level privileges, and applying the principle of least privilege in Power Apps security contexts.

Topics

#Power Apps security#Dataverse security roles#Least privilege#Model-driven apps

Community Discussion

No community discussion yet for this question.

Full PL-100 Practice