Power Platform Column-Level Security Configuration
A local bank uses Microsoft Power Platform apps to store customer data. The bank IT director discovers that all employees can see the social security numbers of their customers. The IT team does not understand how column-level security works and needs help with the design. You need to recommend a solution to the bank that meets the following requirements: • The system must restrict access to customer social security numbers to the vice president of finance only. • The vice president of finance must be able to read and update customer social security numbers. Which two actions should you recommend? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
75% of anonymous learners picked answer BD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests the distinction between table-level and column-level security settings, with the common trap being the selection of table-level controls or missing the creation of the security profile required to assign permissions.
This PL-600 question addresses implementing column-level security in Dataverse to restrict access to sensitive data like social security numbers. The correct solution involves enabling the feature at the column level and configuring a specific security profile for authorized users.
Candidates often select D (Enable column-level security for the social security number column) but fail to select B (Create a column-level security profile), mistakenly believing that enabling the feature alone is sufficient to grant specific user access without defining who has that access.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
To implement row-level or column-level security effectively in Power Platform, you must first enable the security mechanism on the specific target (the column) and then define who has access via a security profile. Option D enables column-level security on the specific 'social security number' column, which is necessary because the requirement is granular to that field. Option B creates the column-level security profile and adds the specific user (Vice President of Finance). Without creating the profile and assigning the user, the enabled security setting has no effect on specific individuals. The combination of enabling the feature on the column and assigning the user via a profile satisfies the requirement to restrict access.Why the Other Options Are Wrong
Option A suggests setting read/update permissions directly, but in the context of Dataverse security profiles, you typically create a profile and assign it; while permission values are part of the profile configuration, the action 'Set the values...' is vague compared to the structural actions of enabling the feature and creating the profile. More importantly, simply setting values without enabling the column-level security (D) or creating the profile (B) does not constitute a complete design solution. Option C enables column-level security for the entire member table, which is too broad and inefficient when only one column requires restriction. Option E, creating a business unit, is an organizational structure concept in Dynamics 365/Power Platform but does not directly solve the technical problem of column-level data masking/access control.Community Comment Notes
Community consensus strongly supports BD. One commenter noted that while three steps might seem logical (Enable, Create Profile, Set Permissions), the exam focuses on the two critical architectural choices: enabling the scope (D) and defining the audience (B). Another comment confirmed BD as correct, aligning with the official answer key.Exam Strategy
When designing security solutions, always distinguish between enabling a security feature (scope) and assigning users to it (assignment). If a question asks for two actions, look for one that activates the feature on the specific object and one that defines the user/group access.
Frequently Asked Questions
Why not enable column-level security for the whole table?
Enabling it for the whole table (Option C) is inefficient and unnecessary when only one specific column contains sensitive data requiring restriction.
Is creating a Business Unit required for this setup?
No. Business Units are for organizational hierarchy in Dynamics 365. Column-level security relies on Security Profiles and Table/Column settings within Dataverse.