Microsoft Certified Power Platform Fundamentals · Free Practice Question Medium

Question 31

Scenario: The law offices of Goodman, Lieber, Kurtzberg & Holliway are a Manhattan-based legal firm specializing in superhuman law.

Lieber wants to allow only certain users to create new environments in Power Platform, while preventing general users from doing so.

How should Lieber configure this?

  • A

    Modify the tenant-level setting for environment creation

  • B

    Create a DLP policy that blocks environment creation

  • C

    Remove the Power Apps license from all users

  • D

    Assign all users the Environment Maker role

Reveal correct answer

Correct answer: A

Explanation

The correct answer is: Modify the tenant-level setting for environment creation

Admins can restrict environment creation by adjusting settings at the tenant level via the Power Platform Admin Centre.

To restrict who can create new environments in Power Platform, Lieber should:

  1. Go to the Power Platform Admin Center and

  2. Modify the tenant-level environment creation settings

This allows you to:

  • Limit environment creation to specific security groups

  • Prevent general (non-admin) users from spinning up new environments

  • Maintain control over data, governance, and resource sprawl

Why the other options are incorrect:

  • Remove the Power Apps license from all users
    Overkill. It would block all Power Apps functionality, not just environment creation.

  • Create a DLP policy that blocks environment creation
    DLP (Data Loss Prevention) policies govern connector/data usage, not environment creation.

  • Assign all users the Environment Maker role
    Opposite of what Lieber wants — this grants app-creation permissions, not restricts them.

How to Configure Tenant-Level Environment Creation Settings:

  1. Go to: Power Platform Admin Center

  2. Click Settings > Power Platform settings

  3. Under Environment creation, choose:

    • Only specific security groups can create environments

  4. Assign the allowed users to that security group

A. Modifying the tenant-level setting for environment creation is the correct approach to control who can create new environments in Power Platform. By adjusting this setting, Lieber can restrict the ability to create environments to only certain users while preventing general users from doing so.

B. Creating a DLP policy that blocks environment creation may help in enforcing data loss prevention measures, but it is not the most direct solution to control who can create new environments in Power Platform. This approach focuses on data protection rather than user permissions for environment creation.

C. Removing the Power Apps license from all users is not the most effective way to control environment creation in Power Platform. This action would impact the users' ability to use Power Apps, but it does not specifically address the issue of restricting environment creation to certain users.

D. Assigning all users the Environment Maker role would grant all users the ability to create environments in Power Platform, which is the opposite of what Lieber wants to achieve. This choice would not restrict environment creation to only certain users as desired.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need