This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Use the following questions to check what you learned about Power Platform tenant and environment security controls.
A user is a member of the security group associated with a production environment but still receives an access denied error. What is the most likely cause?
The user doesn't have a valid Dataverse license.
The IP firewall is blocking access.
The security group hasn't been synced yet.
Your organization wants to prevent session token replay attacks on a Dataverse environment. Which feature should you enable?
IP firewall with IP-address-based cookie binding
Customer Lockbox
Tenant isolation
Which tenant setting should you configure to prevent nonadmin users from creating new production environments?
Set production environment assignments to 'Only specific admins'.
Enable Customer Lockbox.
Associate a security group with the default environment.
A Power Platform administrator enables IP firewall on a production environment. What should they do before switching from audit-only mode to enforcement mode?
Review audit logs to verify that all legitimate traffic comes from allowed IP ranges.
Notify all users via email and enable immediately.
Disable all application users first.
Which combination of controls provides defense-in-depth for a sensitive production environment?
Security group (identity) plus IP firewall (network) plus security roles (data access)
IP firewall plus Customer Lockbox plus tenant isolation
Conditional access plus sharing limits plus data loss prevention policies
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?