Power Platform Networking for Azure and On-Premises Integration

Design integrations
Answer Correct answer: B, C — Implement a VPN and use Azure ExpressRoute to establish secure, dedicated network connectivity for Power Platform environments.

A company has 2 Microsoft Power Platform environment. The company requires a solution that provides integration with Azure services and on-premises data sources. The integration must provide secure and efficient communication among the Microsoft Power Platform components, Azure services, and data sources. You need to design a networking solution for the company. What are two possible ways to incorporate the design? Each correct answer presents a complete solution. NOTE: Each correct selection is worth one point.

  1. Configure Azure Virtual Network service endpoints.
  2. Implement a virtual private network for Microsoft Power Apps to directly access on-premises systems. Correct Answer
  3. Use Azure Express Route for dedicated connections between Azure services and Microsoft Power Platform environments. Correct Answer
  4. Configure Azure Firewall to protect SQL Server instances.
  5. Configure Microsoft Entra ID to restrict access to Microsoft Power Platform environments.

Community Votes

BC
75%
AC
25%

75% of anonymous learners picked answer BC. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests hybrid networking design for Power Platform, where the common trap is confusing network security features (like service endpoints or Entra ID) with actual connectivity solutions.

Designing a networking solution for Microsoft Power Platform to integrate with Azure and on-premises data sources requires secure hybrid connectivity. This page establishes that using a VPN and Azure ExpressRoute are the two correct networking designs.

Choosing Azure Virtual Network service endpoints (Option A) because they are Azure networking features, even though they secure PaaS access from a VNet rather than establishing the integration path from Power Platform.

Community Discussion (3 comments)

loftuscheek 👍 1 Selected: BC
implement a VPN use azure express route
WASSIM2020 👍 2 Selected: BC
Correct answer is BC Implementing a VPN allows Microsoft Power Apps to connect securely to on-premises systems. The VPN connection extends your on-premises network to Azure or Power Apps, providing secure communication between the cloud and on-premises environments. Azure ExpressRoute creates a private, dedicated connection between your on-premises network (or other locations) and Azure services. This provides a highly reliable and secure connection for Azure services, including the Power Platform, without using the public internet.
Tootru2bReal 👍 1 Selected: AC
Should be A & C. I've personally had to do A for a custom connector used by PowerApps to connect to an Azure Managed SQL instance (different from just a regular Azure Sql DB). Managed instance is automatically protected on a virtual network plus firewall configuration. Have to configure the endpoints to open access. And Azure Express Route is known for secure and private connections to resources.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Implementing a virtual private network (Option B) provides a secure encrypted tunnel over the internet, extending the on-premises network to Azure and allowing Power Platform components to communicate securely with on-premises data sources. Using Azure ExpressRoute (Option C) provides a private, dedicated, and reliable connection that bypasses the public internet, ensuring secure and efficient communication between Power Platform environments, Azure services, and on-premises systems. Both are standard hybrid networking architectures that fulfill the requirement for secure and efficient communication.

Why the Other Options Are Wrong

Azure Virtual Network service endpoints (Option A) secure Azure PaaS resources to a virtual network but do not establish the initial connectivity path between Power Platform and Azure or on-premises systems. Azure Firewall (Option D) is a network security appliance used to filter and protect traffic, not a connectivity solution to integrate environments. Microsoft Entra ID (Option E) is an identity and access management service, which controls authentication and authorization rather than providing network-level communication.

Community Comment Notes

Some learners argue for Azure Virtual Network service endpoints, with one noting they "have to configure the endpoints to open access" for Azure SQL Managed Instances. However, service endpoints only secure existing VNet-to-PaaS traffic and do not establish the foundational network integration path required by the question. The community consensus correctly identifies VPN and ExpressRoute as the true connectivity solutions, as WASSIM2020 noted regarding how a "VPN connection extends your on-premises network to Azure".

Official Reference

Exam Strategy

When asked for networking solutions to integrate Power Platform with on-premises or Azure, focus on hybrid connectivity options like VPN and ExpressRoute. Do not select security features (like firewalls or Entra ID) or VNet access restrictions (like service endpoints) as they do not establish the communication channel itself.

Related Analysis

← Back to PL-600 Study Guide