Power Platform Data Access Design for Multinational Corp
A multinational corporation is deploying a Microsoft Power Platform solution to manage its sales processes across the following regions: North America, Europe, and Asia. Each region operates independently but reports to a global headquarters. The company has several business units that correspond to each region. Within each business unit are multiple teams based on countries/regions. Company employees have the following requirements: • Sales representatives must have access only to data relevant to their specific country/region. • Regional managers must be able to view and manage data across all areas within their region. • Some global analysts require read-only access to sales data across the corporation by using third-party tools. • External contractors need limited access to the system to input their progress. You need to design a solution for the company. What should you do?
Community Votes
80% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
Tests the ability to distinguish between governance policies (DLP) and granular data access controls (RLS), with the common trap being the selection of DLP as a data restriction tool rather than an app usage policy.
This question explores designing data access controls in Microsoft Power Platform for a multinational organization with hierarchical reporting structures. It establishes that Row-Level Security (RLS) is the appropriate mechanism to restrict data visibility based on user attributes like country or region.
Option B (DLP Policy) is chosen by some learners who confuse data protection policies with row-level data filtering; DLP prevents apps from connecting to certain data sources but does not hide specific rows within a dataset.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Correct answer: A — Implementing row-level security allows you to define rules that filter data records based on the logged-in user's attributes, such as their assigned country or region. This perfectly satisfies the requirement for sales representatives to see only their specific country's data while allowing regional managers to view broader scopes through different roles.Why the Other Options Are Wrong
Option B is incorrect because Data Loss Prevention (DLP) policies control which connectors can be used together (e.g., preventing Power Apps from writing to SharePoint), not the internal visibility of rows within Dataverse. Option C fails because organization-level access would grant sales reps visibility across all regions, violating the "specific country/region" constraint. Option D is invalid because using a single business unit contradicts the requirement for independent regional operations and makes it difficult to enforce hierarchical access boundaries effectively.Community Comment Notes
The community consensus strongly favors Option A, with users noting that it is the only viable option for granular data separation. One user dismissed Option D as unconvincing for a worldwide company, while another highlighted that RLS is the standard solution for this type of hierarchical data access challenge.Official Reference
Exam Strategy
When designing solutions involving 'access only to specific data' based on user location or role, always consider Row-Level Security first. Reserve DLP policies for scenarios where you need to prevent data exfiltration via unauthorized connector combinations.
Frequently Asked Questions
Why isn't DLP used to restrict data?
DLP policies restrict which connectors can be used in apps, not which rows of data a user can see within a supported data source.
Can RLS handle multiple regions?
Yes, RLS rules can be configured to allow users to see data for their own region or all data for their parent region based on their role.