Microsoft Certified Power Platform Functional Consultant Associate · Free Practice Question Medium

Question 43

A default environment is automatically created for you when you sign up for Power Apps, Dynamics 365, or if you have a Microsoft 365 account with Microsoft. At least one environment will always be designated as the default when you start to work with Microsoft Dataverse.

After creating an environment, you can create a new instance of a Microsoft Dataverse database. Users from Azure Active Directory that are associated with your tenant are automatically added to the environment.

There are predefined security roles that reflect common user tasks with access levels which are defined to match the security best-practice goal.

Which of these predefined security roles is described by: Has full permission to customize the environment. Can only view records for environment entities that they create.

  • A

    Delegate

  • B

    Environment Maker

  • C

    System Customizer

  • D

    System Administrator

  • E

    Basic User

Reveal correct answer

Correct answer: C

Explanation

A default environment is automatically created for you when you sign up for Power Apps, Dynamics 365, or if you have a Microsoft 365 account with Microsoft. At least one environment will always be designated as the default when you start to work with Microsoft Dataverse.

After creating an environment, you can create a new instance of a Microsoft Dataverse database. Users from Azure Active Directory that are associated with your tenant are automatically added to the environment.

User security roles control a user’s access to data through a set of access levels and permissions. The combination of access levels and permissions that are included in a security role sets limits on the user’s view of and interactions with that data.


Tip: Users who are automatically added to the default environment have the Common Data Service (CDS) User role enabled, but users who are automatically added to another environment will not have any user roles enabled.


Security roles can also be associated with an Azure AD group. MS recommends that you create Azure AD groups and associate roles with those security groups to simplify permissions and data access.


Tip: The user security roles control run-time access to data and are separate from the environment roles that govern environment administrators and environment makers. The two environment roles that are built into every environment are System Administrator and Environment Maker. All other roles are user security roles.


An administrative user who has been added to the Environment Admin role uses the following steps to assign new groups or users to the environment and security roles within that environment:

1. Sign in to the Power Platform Admin Centre.

2. Select the environment in the list of environments that you want to administer.



3. In the Access section, verify that the user already exists in the environment by selecting See all under Users.



4. If a user does not exist in the environment, you can add the user here in the Power Platform admin centre. Add the user by selecting the Add user button and then entering the user’s email address into your organization.



5. Wait for a few minutes to verify that the user has been added to the list of users in the environment.

6. Select the user's name from the list of users in the environment. A new tab will open with the details of that user account.

7. Select the Manage Roles tab.

8. Assign the System Administrator role to the user by selecting the check box next to the role name.



9.Select OK to update the assignments to the user within that environment.

The following table describes each of the predefined security roles that reflect common user tasks with access levels that are defined to match the security best-practice goal, which is to provide access to the minimum amount of business data that is required to use the app.



Create a custom security role

If you need a custom security role, you can create a new security role with the following steps. The custom security role that you create is only available within a single environment where it is created. The custom role is not available in any other environment.

1. Sign in to Power Platform.

2. Select the environment in the list of environments that you want to administer.

3. In the Access section, select See all under Security Roles.



4. Select New role at the top.

5. Add a name and fill out the settings for the new role by using the tabs.



6. Click on the Custom Entities tab and adjust user security settings for each table (entity).



7. Click Save and close at the top.

You have now added user permissions and created a custom security role.

A. The Delegate role in Microsoft Dataverse is not a predefined security role that reflects common user tasks with specific access levels. This role is not associated with the described permissions of having full permission to customize the environment and only viewing records for environment entities that they create.

B. The Environment Maker role in Microsoft Dataverse is responsible for creating and managing environments, but it does not have full permission to customize the environment. This role focuses on environment provisioning and management tasks rather than customization permissions.

C. The System Customizer role in Microsoft Dataverse has full permission to customize the environment, including modifying entity forms, views, fields, and business rules. However, users with this role can only view records for environment entities that they create, ensuring data security and privacy.

D. The System Administrator role in Microsoft Dataverse has full permissions to manage all aspects of the environment, including customization, security, and data management. While this role has extensive permissions, it does not align with the specific description of only being able to view records for environment entities that the user creates.

E. The Basic User role in Microsoft Dataverse has limited permissions and is primarily focused on viewing and interacting with records within the environment. This role does not have the ability to customize the environment or have full permissions for customization tasks.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need