Dataverse Security Strategy for Departmental Apps

Answer Correct answer: B — Use a business unit for each department with a security role for each department and a hierarchy security model.

Case study - This is a case study. Case studies are not timed separately. You can use as much exam time as you would like to complete each case. However, there may be additional case studies and sections on this exam. You must manage your time to ensure that you are able to complete all questions included on this exam in the time provided. To answer the questions included in a case study, you will need to reference information that is provided in the case study. Case studies might contain exhibits and other resources that provide more information about the scenario that is described in the case study. Each question is independent of the other questions in this case study. At the end of this case study, a review screen will appear. This screen allows you to review your answers and to make changes before you move to the next section of the exam. After you begin a new section, you cannot return to this section. To start the case study - To display the first question in this case study, click the Next button. Use the buttons in the left pane to explore the content of the case study before you answer the questions. Clicking these buttons displays information such as business requirements, existing environment, and problem statements. If the case study has an All Information tab, note that the information displayed is identical to the information displayed on the subsequent tabs. When you are ready to answer a question, click the Question button to return to the question. Background - VanArsdel, Ltd. builds custom homes. The company has one Azure tenant and uses multiple systems to manage the sales, construction, and warranties of the homes. The company has three departments: sales, construction, and warranty. Sales, contract, and warranty information is not shared among the departments. The owner of VanArsdel, Ltd. requires a consolidated system that the company can use to track each home’s progress. Sales - Current environment - • Company employees use Microsoft Outlook for all communications. • Company employees use Microsoft Word to create sales contracts. • Employees in the sales department are frequently in different locations and work different hours from each other. • Employees in the sales department use a Contracts team in Microsoft Teams to collaborate. • The company uses a third-party marketing tool to update contacts every day. Requirements - • Contacts’ names must be formatted before they are imported from the third-party marketing tool. • The company must retain contracts for five years. • The company requires that the sales department display the All Contracts view in Microsoft Teams. • All contract information must be stored in the All Contracts view. • Contracts must not be lost if a device is lost or stolen. Issues - • Employees in the sales department store contracts on their local computers. • The construction team receives a copy of a contract only when the sale of a home is complete. Construction - Current environment - • Employees in the construction department use Project Online to manage schedules. • Employees in the construction department use Microsoft Excel to manage costs of projects. • The main supplier of construction materials provides an API to the company. The company uses the API to manage suppliers for projects in near real time. Requirements - • Employees in the construction department must be able to demonstrate how their work is performed rather than document their process. • The company requires that project schedules be created less than a week after a contract is signed. • A field must sum up the costs of the materials. Issues - • Employees in the construction department are unable to schedule resources because they are not informed of future projects. • Employees in the construction department currently enter basic project information manually for each software application. Warranty - Current environment - • Employees in the warranty department use Excel to track project issues and resolutions. • The company requires that employees in the warranty department meet with each other in person to discuss their job roles. Requirements - • The company requires that warranty claims be resolved in less than a month. • The company requires that all claims be entered in the system along with their related issues. • If a claim is found to be invalid, the company requires that the claim and its related issues be deleted. Issue - • Employees in the warranty department report that they are frequently sent to homes without knowledge of what is in scope for the project. Requirements - • The new system must use the development and production environments. • The development environment must be the master of all changes. • All table changes must be added ta solution. Changes to the solution must not be allowed to be made in the production environment. • Each department must have a custom app. Employees must be able to access only their department’s app. • All sales, contract, and warranty data must be shared among the departments. • The project manager must be solely responsible for creating and owning the deployment plan for projects. • All projects must run by using the Agile methodology. • The deployment plan must include the environment setup, training plan, rollout strategy, and deployment support. Issue - The IT manager reports that the deployment plan is not complete. You need to design the security strategy for employees. What should you use?

  1. a business unit for each department with one security role
  2. a business unit for each department with a security role for each department and a hierarchy security model Correct Answer
  3. one business unit with one security role and a hierarchy security model
  4. one business unit with a security role for each department

Community Votes

B
62%
D
38%

62% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to isolate data access per department while maintaining organizational structure; the trap is assuming a single unit suffices because data must eventually be shared.

Designing a secure Power Platform environment requires aligning business units and security roles with departmental isolation requirements. This analysis confirms that separating departments into distinct business units with specific roles is the correct approach.

Choosing one business unit (Options C or D) fails to provide the necessary logical separation for department-specific apps and initial data isolation described in the current environment.

Community Discussion (6 comments)

loftuscheek 👍 1 Selected: B
B is correct , D is bad practice
Kyol 👍 1 Selected: D
100% D, don't believe the hype.
FaresAyyad 👍 1 Selected: B
B. a business unit for each department with a security role for each department and a hierarchy security model
WASSIM2020 👍 1 Selected: B
Answer B A business unit for each department creates logical separation between the sales, construction, and warranty departments. This ensures that each department’s data and processes are isolated, which is important because the departments need to access only their own data and processes. A hierarchy security model is useful because it allows for role-based access across different levels of the organization. For instance, managers may need access to data across their entire department, while individual employees may only need access to data relevant to their role.
8743423 👍 2 Selected: B
B. a business unit for each department with a security role for each department and a hierarchy security model
HX 👍 2 Selected: D
Some observation: Issues with Data Sharing: Sales, construction, and warranty information is not shared among departments. The construction team lacks visibility into contracts until sales are completed. Warranty employees frequently lack project scope details when visiting homes. Requirements for Collaboration: "All sales, contract, and warranty data must be shared among the departments." Employees must have access only to their department's app but data must flow seamlessly between departments.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is the correct design because it establishes clear boundaries between the Sales, Construction, and Warranty departments. By creating a business unit for each department, you enforce the requirement that "Employees must be able to access only their department’s app" and respect the current state where information is not shared. Assigning a security role for each department ensures that permissions are granular and aligned with job functions. The hierarchy security model allows for scalable permission management across these units, ensuring that as the organization grows, security policies remain consistent and manageable.

Why the Other Options Are Wrong

Option A lacks the hierarchy security model, which is essential for managing permissions across multiple business units efficiently in a complex enterprise scenario. Option C suggests a single business unit, which contradicts the need for departmental isolation and custom apps restricted to specific departments. Option D also uses a single business unit, failing to provide the logical separation required to prevent cross-departmental data leakage before the consolidation phase is fully implemented and secured.

Community Comment Notes

The community is divided, but the majority supports B. As user WASSIM2020 noted, "A business unit for each department creates logical separation... important because the departments need to access only their own data." Some users like HX and Kyol argue for D, suggesting that since data must be shared, separate units are unnecessary. However, this overlooks the requirement for department-specific apps and the principle of least privilege during the development and initial deployment phases.

Official Reference

Exam Strategy

Always map the 'access only their department's app' requirement to Business Units. If departments need isolated views or apps initially, they should have separate Business Units, even if data sharing is planned later.

Frequently Asked Questions

Why use hierarchy security model?

It simplifies permission inheritance and management across multiple business units and roles.

Can we share data with separate business units?

Yes, by using team memberships or explicit record-level sharing rules across business units.

Related Analysis

← Back to PL-600 Study Guide