Power Platform Data Access Design for Multinational Corp

Answer Correct answer: A — Implement row-level security to restrict data visibility based on user attributes such as country or region.

A multinational corporation is deploying a Microsoft Power Platform solution to manage its sales processes across the following regions: North America, Europe, and Asia. Each region operates independently but reports to a global headquarters. The company has several business units that correspond to each region. Within each business unit are multiple teams based on countries/regions. Company employees have the following requirements: • Sales representatives must have access only to data relevant to their specific country/region. • Regional managers must be able to view and manage data across all areas within their region. • Some global analysts require read-only access to sales data across the corporation by using third-party tools. • External contractors need limited access to the system to input their progress. You need to design a solution for the company. What should you do?

  1. Implement row-level security. Correct Answer
  2. Implement a DLP policy to restrict data that will be shared from Microsoft Dataverse.
  3. Use a global security role with organization-level access for sales representatives.
  4. Use a single default business unit and manage data access through security roles.

Community Votes

A
80%
B
20%

80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests the ability to distinguish between governance policies (DLP) and granular data access controls (RLS), with the common trap being the selection of DLP as a data restriction tool rather than an app usage policy.

This question explores designing data access controls in Microsoft Power Platform for a multinational organization with hierarchical reporting structures. It establishes that Row-Level Security (RLS) is the appropriate mechanism to restrict data visibility based on user attributes like country or region.

Option B (DLP Policy) is chosen by some learners who confuse data protection policies with row-level data filtering; DLP prevents apps from connecting to certain data sources but does not hide specific rows within a dataset.

Community Discussion (4 comments)

loftuscheek 👍 1 Selected: A
answer is A
inboxofdt 👍 1 Selected: B
I'd eliminate C and D first: not C - it won't restrict their access to specific country/region not D - single business unit sounds not very convincing for a worldwide company with external contractors. Now, between A and B... honestly, I'd just guess that it's B, as setting up row-level security for all these cases would be a six-month project..
Kyol 👍 1 Selected: A
Security role for a third party? "ok"
Tootru2bReal 👍 2 Selected: A
Option A - the only viable option. I looked at D briefly but no, not with the organization's setup and separation of countries, regions, and units.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Correct answer: A — Implementing row-level security allows you to define rules that filter data records based on the logged-in user's attributes, such as their assigned country or region. This perfectly satisfies the requirement for sales representatives to see only their specific country's data while allowing regional managers to view broader scopes through different roles.

Why the Other Options Are Wrong

Option B is incorrect because Data Loss Prevention (DLP) policies control which connectors can be used together (e.g., preventing Power Apps from writing to SharePoint), not the internal visibility of rows within Dataverse. Option C fails because organization-level access would grant sales reps visibility across all regions, violating the "specific country/region" constraint. Option D is invalid because using a single business unit contradicts the requirement for independent regional operations and makes it difficult to enforce hierarchical access boundaries effectively.

Community Comment Notes

The community consensus strongly favors Option A, with users noting that it is the only viable option for granular data separation. One user dismissed Option D as unconvincing for a worldwide company, while another highlighted that RLS is the standard solution for this type of hierarchical data access challenge.

Official Reference

Exam Strategy

When designing solutions involving 'access only to specific data' based on user location or role, always consider Row-Level Security first. Reserve DLP policies for scenarios where you need to prevent data exfiltration via unauthorized connector combinations.

Frequently Asked Questions

Why isn't DLP used to restrict data?

DLP policies restrict which connectors can be used in apps, not which rows of data a user can see within a supported data source.

Can RLS handle multiple regions?

Yes, RLS rules can be configured to allow users to see data for their own region or all data for their parent region based on their role.

Related Analysis

← Back to PL-600 Study Guide