exam questions

Exam PL-200 All Questions

View all questions & answers for the PL-200 exam

Exam PL-200 topic 1 question 40 discussion

Actual exam question from Microsoft's PL-200
Question #: 40
Topic #: 1
[All PL-200 Questions]

HOTSPOT -
You are designing the organization structure for a company that has 5,000 users.
You need to configure security roles for the company while minimizing administrative effort.
What should you do? To answer, select the appropriate options in the answer area.
NOTE: Each correct selection is worth one point.
Hot Area:

Show Suggested Answer Hide Answer
Suggested Answer:
Box 1: Create a new team, and the business unit users, and the assign the security role to the team.
Change the business unit for a team

Important -
By changing the business unit for a team, you can remove all security role assignments for the team. At least one security role must be assigned to the team in the new business unit.
1. Select an environment and go to Settings > Users + permissions > Teams.
2. Select the checkbox for a team name.
3. Screenshot selecting a team.
4. On the menu bar, select Change Business Unit.
5. In the Change Business Unit dialog box, select a business unit. Enable Move records to new business unit to move to a new business unit. Select OK.
Box 2: Grant the user a security role from the child business unit.
Incorrect:
* Grant the user the Parent: Child Business Units security permission.
Too much permissions granted.
The application refers to this access level as Parent: Child Business Units.
This access level gives a user access to records in the user's business unit and all business units subordinate to the user's business unit.
* Grant the user a security role from the root business unit.
Too much permissions granted.
Reference:
https://docs.microsoft.com/en-us/power-platform/admin/create-edit-business-units https://docs.microsoft.com/en-us/power-platform/admin/security-roles-privileges

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Dotzs
Highly Voted 1 year, 9 months ago
Answer is: Box 1 - 1 Box 2 - 2 - The business unit will have a default team, so just assign to roles to it instead of creating a new Team - Parent: Child can only be assigned as a permission and not a security role, e.g you can give Parent: Child... on create, write, delete... on an entity within a security role.
upvoted 34 times
TonyTeeTee
1 year, 9 months ago
Correctomundo!
upvoted 2 times
...
Luay
1 year, 3 months ago
It's such a relief to open discussion to see people agree with you, and you're not really wrong as the website answer says.
upvoted 4 times
...
MLenja
1 year, 9 months ago
Box 1 - 3 if you want apply security roles to everyone in organisation you need to "add business unit users" to the team. User´s are not by default part ot the team. You need to add them to the team.
upvoted 9 times
...
...
emapedrozo
Highly Voted 1 year, 7 months ago
Both are incorrect: For Box 1 the correct answer should be option 1 as the docs claims: "You can assign a security role to the business unit's default team. This is done to simplify security role management where all your business unit team members can share the same data access." And for Box 2, the correct answer should be Option 2, as docs claims: "Deep. This access level gives a user access to records in the user's business unit and all business units subordinate to the user's business unit. Users who have Deep access automatically have Local and Basic access, also. Because this access level gives access to information throughout the business unit and subordinate business units, it should be restricted to match the organization's data security plan. This level of access is usually reserved for managers with authority over the business units. The application refers to this access level as Parent: Child Business Units."
upvoted 7 times
...
b304b2c
Most Recent 2 months, 3 weeks ago
was on test May 14 2024
upvoted 4 times
YessinZ
3 days, 3 hours ago
any suggestions about the right answers?
upvoted 1 times
...
...
jkaur
4 months ago
1 and 2
upvoted 1 times
...
61be873
4 months, 1 week ago
Each business unit has a default team. You can't update the default team's name, nor delete the default team. You can't add or remove users from the business unit's default team. However, you can change the user's current business unit to the new business unit and the user will automatically be added to the business unit's default team. You can assign a security role to the business unit's default team. This is done to simplify security role management where all your business unit team members can share the same data access. https://learn.microsoft.com/en-us/power-platform/admin/create-edit-business-units
upvoted 4 times
...
MrEz
7 months, 1 week ago
In a setting with sub-sub business units, in the background the system creates several security role records (including the parent root role), each one of them related to a business unit all 3 are wrong a) As it is written I would understand to grant(apply) a user in the A-Team business unit the security role record ‘from’ the sub business unit A1. I would not do that (maybe wit xml edit or any ploy you could manage this). B) I jumped for this solution first but there are 2 reasons why it is down wrong: first, the permissions are granted on roles, not on users (wrong entity!). Second, it is not a permission but an access level. c) Means the opposite from a) give a user e.g. in business unit B-Team the (parent root) role record ‘from’ root business unit CRM... Which answer is the least wrong? The answer B) that has 2 wrong components or one of the others..?
upvoted 1 times
...
MrEz
7 months, 1 week ago
In a setting with sub-sub business units, in the background the system creates 5 security role records (including the parent root role), each one of them related to a business unit. all 3 are wrong a) As it is written I would understand to grant(apply) a user in the A-Team business unit the security role record ‘from’ the sub business unit A1. I would not do that (maybe wit xml edit or any ploy you could manage this). B) I jumped for this solution first but there are 2 reasons why it is down wrong: first, the permissions are granted on roles, not on users (wrong entity!). Second, it is not a permission but an access level. c) Means the opposite from a) give a user e.g. in business unit B-Team the (parent root) role record ‘from’ root business unit CRM... Which answer is the least wrong? The answer B) that has 2 wrong components or one of the others..?
upvoted 1 times
...
MrEz
7 months, 1 week ago
all 3 are wrong a) As it is written I would understand to grant(apply) a user in the A-Team business unit the security role record ‘from’ the sub business unit A1. I would not do that (maybe wit xml edit or any ploy you could manage this). B) I jumped for this solution first but there are 2 reasons why it is down wrong: first, the permissions are granted on roles, not on users (wrong entity!). Second, it is not a permission but an access level. c) Means the opposite from a) give a user e.g. in business unit B-Team the (parent root) role record ‘from’ root business unit CRM... Which answer is the least wrong? The answer B) that has 2 wrong components or one of the others..? I would go for b.
upvoted 1 times
...
Uginy
9 months, 3 weeks ago
Box 2 - 1 is correct. You need to allow access to just one particular BU. Not all children.
upvoted 1 times
...
Radoslavov
1 year, 4 months ago
I think the options are correct 1 and 3. If you look a bit deeper to the question it says "5,000 users. You need to configure security roles for the company while minimizing administrative effort" Q1: Apply a security tole to everyone in A business unit (it doesn't specify that this is the root one) So apart of the root BU, if we have another one, we need to create a new team for that BU and assign it to the BU as by default the new BU doesn't have team when was created. So this is the minimum effort to apply a security role to everyone from A BU. Q2: Ensure an individual can see records in THEIR current business unit and a CHILD unit - if i'm the admin, i will use the new functionality "Matrix data access structure" to provide access to a data from another BU by assigning a role from that unit, instead of going to the role in the user's BU and modify the level one-by-one, which will apply for EVERY user in that BU and the question also says "Ensure an individual"
upvoted 1 times
Radoslavov
1 year, 4 months ago
so you just need to "Create a new team, add the business unit, and then assign the security role to the team "
upvoted 1 times
CalebXin
1 year, 4 months ago
if the team is created automatically, you just need to assign users to that team, no need to create a new team and add the business unit..", so the answer should be 1st.
upvoted 3 times
...
...
Radoslavov
1 year, 4 months ago
ignore this part of my comment: we need to create a new team for that BU and assign it to the BU as by default the new BU doesn't have team when was created. IT IS CREATED ACTUALLY BY DEFAULT AND LINKED TO THE BU
upvoted 2 times
...
...
nilakuma
1 year, 5 months ago
Question was on test 3/2023
upvoted 2 times
...
LukeB22
1 year, 7 months ago
Box 1 Is very likely the first option: "Every Business Unit has one default team that is automatically created when the Business Unit is created" If they want to apply the security role to every person in a business unit then this is the fastest and easiest way, Creating a new team is unnecessary
upvoted 1 times
LukeB22
1 year, 7 months ago
I should also add: "The default team members are managed by Dataverse and always contain all users associated with that Business Unit. You can’t manually add or remove members from the default team, they're dynamically adjusted by the system as new users are associated/disassociated with business units." So if you manually make a team and add the members then they will still have the security roles even though they may not be in the business unit anymore!
upvoted 2 times
...
...
Momo84
1 year, 7 months ago
This is a horrible question. I would say that q1 = a1 and q2 = a1 BUT you can't directly add a security role from another BU, that can only be done by adding the user to a Team from another BU that has a security role applied to it AND you can't add a user to a default BU Team. I think they've made this purposefully confusing.
upvoted 1 times
...
abhigang51
1 year, 8 months ago
this question is kept on 23/11/2022
upvoted 2 times
...
et_learner
1 year, 9 months ago
If you read the question `you need to configure security roles for the company while minimizing administrative effort`, then the box 1 will be option 1, if minimizing administrative effort not mentioned, option 3 is also correct.
upvoted 7 times
...
mr452
1 year, 10 months ago
Box 2 Parent: Child Business Units "Deep. This access level gives a user access to records in the user's business unit and all business units subordinate to the user's business unit. Users who have Deep access automatically have Local and Basic access, also. Because this access level gives access to information throughout the business unit and subordinate business units, it should be restricted to match the organization's data security plan. This level of access is usually reserved for managers with authority over the business units. The application refers to this access level as Parent: Child Business Units" https://learn.microsoft.com/en-us/power-platform/admin/security-roles-privileges
upvoted 3 times
OldHand1
1 year, 9 months ago
I think MS are being a bit sneaky here, it says ensure an 'individual' as in 'one' user can see records in the child business unit. If you grant parent-child permission, everybody in the parent will be able to see.
upvoted 1 times
...
...
allesglar
1 year, 10 months ago
I would choose answer 1 for both questions.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago