PL-400 · Microsoft Power Platform Developer

PL-400 Cheat Sheet: Task-to-Tool Quick Reference

Verified against Microsoft Learn Sept 7, 2026

TL;DR

This reference is organized by what you're trying to build, not by exam domain — because PL-400 scenario questions describe a task and expect you to name the right tool, not recite a domain label. Jump to the task ledger below, then use the pattern-recognition table to translate exam wording into the concept it's testing.

MSCertQuiz sells a 500-question PL-400 practice bank; this cheat sheet is maintained by the same team and reflects patterns we see candidates get wrong most often in that bank, not just a copy of the Microsoft study guide's domain list.

Exam Snapshot

CertificationMicrosoft Certified: Power Platform Developer Associate
Passing score700 / 1000 (scaled score)
Typical priceUS$165 (Associate-level baseline; varies by region)
RenewalFree online assessment every 12 months
Largest domainExtend the platform — 30–35%

Full domain breakdown and study-hour allocation: see the PL-400 study guide.

If You Need To... Use This

You need to...Reach forKey detail
Cancel an invalid operation before it touches the databasePlug-in, PreValidation stageRuns before security checks and before the transaction opens — cheapest place to cancel
Change a field value just before the record savesPlug-in, PreOperation stageRuns inside the transaction; avoid canceling here — it forces a rollback
React after a save completes without slowing the user downPlug-in, PostOperation stage + Asynchronous modeAsync plug-ins can only be registered on PostOperation
Read the value a field had before an Update changed itPre-image on the step registrationPre-images capture attribute state before the core operation
Read attribute values only available after the operation ranPost-image on the step registrationPost-images capture attribute state after the core operation
Add an operation that isn’t a Create, Update, or DeleteCustom API (bound or unbound)Registered like a plug-in via the Plug-in Registration Tool
Build a reusable custom input/output control for a form or canvas appPCF (Power Apps component framework) code componentImplements init, updateView, getOutputs, destroy
Store a value that must differ between dev, test, and prodEnvironment variableDefinition travels in the solution; value is supplied per target environment
Let a flow or canvas app call your own REST APICustom connector from an OpenAPI definitionWraps a public or private REST/SOAP API for the platform
Authenticate a custom connector against an Entra ID–protected APIOAuth 2.0, identity provider = Microsoft Entra IDClient credentials grant type is not supported — use authorization code flow
Run a long-running or scheduled backend job against DataverseAzure Function, managed identity authenticationRemoves the need to rotate client secrets for the connection
Notify an external system the moment a Dataverse record changesService endpoint (webhook, Azure Service Bus, or Azure Event Hub)Registered through the Plug-in Registration Tool
Sync only what changed in Dataverse, not the full table every timeChange trackingReturns a token to fetch just the delta since the last sync
Upsert records from a source system with no Dataverse GUIDAlternate key + UpsertRequest messageAvoids creating duplicate rows when only a business key is known
Run business logic from a canvas app without writing a plug-inPower Automate cloud flow called from the appKeeps logic declarative and outside compiled code
Fix a canvas app that’s slow against a large data sourceDelegable formulas + pre-loading dataNon-delegable formulas silently cap results at the record limit
Show a command only to users with a specific security roleRibbon/command bar rule with Power Fx or JavaScriptEvaluated via the Client API at form load
Send a user to a custom page from a form commandClient API navigation methodPart of the model-driven client scripting surface
Promote a solution through dev/test/prod without manual reconfigPower Platform Pipelines or Build Tools + deployment settings filePre-populates connection references and environment variables per environment
Limit what a plug-in’s calling user context can touchDataverse security role scoped to least privilegeApplies to the “Run in User’s Context” setting on the step

Pattern Recognition: If the Question Says X, Think Y

PL-400 scenario questions rarely say "PreValidation stage" outright — they describe the timing and consequence, and expect you to name the mechanism. Recognizing these phrasings is often worth more than memorizing the concept in isolation.

If the question says...Think...
“Before the record is saved, and the operation should be canceled if invalid”PreValidation stage
“Modify a value just before it’s written, still part of the same transaction”PreOperation stage
“After the save finishes, without adding latency for the user”PostOperation + Asynchronous execution
“Needs to know what the field used to contain”Pre-image
“The operation doesn’t map to Create, Update, or Delete”Custom API
“Same custom control reused across multiple forms or apps”PCF code component
“Value must be different once it reaches production”Environment variable
“Wrap an existing REST API so Power Automate can call it”Custom connector
“Authenticate using the org’s Azure AD / Entra ID sign-in”OAuth 2.0, Microsoft Entra ID provider
“Sync changes only, not the whole table on every run”Change tracking
“Source system doesn’t know the Dataverse record ID”Alternate key + Upsert

Plug-in Stage Quick Map

StageRunsIn transaction?Typical use
PreValidationBefore security checks, before main operationNoCancel an invalid operation cheaply
PreOperationBefore main operationYesModify entity attribute values before save
MainOperationThe core platform operation itselfYesReserved — custom APIs and custom virtual table data providers only
PostOperationAfter main operationYes (sync) or outside it (async)React to a completed change; only stage that supports async mode

Source: Microsoft Learn, event execution pipeline.

PCF Lifecycle Quick Map

MethodCalled whenRequired?
initComponent first loads on the pageYes
updateViewAny bound property, dataset, or context value changesYes
getOutputsFramework needs current output values, after notifyOutputChangedNo — optional
destroyComponent removed from the DOMYes

Source: Microsoft Learn, code components overview.

Custom Connector Auth Quick Map

Auth typeUse when
No authenticationThe API is public and anonymous
Basic authenticationA simple username/password is all the API needs
API KeyThe API expects a key in a header or query string
OAuth 2.0Delegated user identity is required, e.g. an Entra ID–protected API

Source: Microsoft Learn, connection parameters.

Common Gotchas

  • →MainOperation is reserved for custom APIs and custom virtual table data providers — it is not an option for ordinary business logic.
  • →Canceling in PreOperation forces a full transaction rollback; cancel in PreValidation instead whenever possible.
  • →Asynchronous execution mode can only be registered on the PostOperation stage.
  • →Never include the primary key in filtering attributes — it is always present on Update and negates every other filter.
  • →context.webAPI is not available when a PCF component runs inside a canvas app — always check host API availability before using it.
  • →Custom connector OAuth 2.0 does not support the client credentials grant type — only the authorization code flow issues the refresh tokens it needs.
  • →Only the environment variable definition should travel inside a managed solution; values are supplied per target environment, not exported with the solution.

Drill this against real scenario questions

The task ledger above tells you the mechanism. Practice tells you how PL-400 disguises which mechanism it wants.

Start Free Practice →

Frequently Asked Questions

Is this cheat sheet enough to pass PL-400 on its own?

No. It assumes you already understand the underlying concepts and just need a fast lookup for exam day or a final review pass. Pair it with hands-on practice and the PL-400 study guide if you're still learning the material for the first time.

How is this different from the PL-400 study guide?

The study guide explains what each domain tests and why, with a study-time plan. This cheat sheet skips the explanation and organizes the same underlying knowledge by task — "what do I reach for when I need to do X" — for quick lookup rather than learning from zero.

Can I print this cheat sheet?

Yes — it's plain tables and text with no interactive elements, so your browser's print function renders it cleanly on paper or as a PDF for offline review.

Why isn't there a percentage/weighting column here?

Domain weightings tell you how to allocate study time, not which tool to pick during the exam — that's exactly what the study guide is for. This page is organized by task because that's how PL-400 scenario questions are actually phrased.

What if a scenario doesn't match any row exactly?

Work backward from timing and consequence: does it need to happen before or after the save, inside or outside the transaction, synchronously or not? Those four questions narrow almost every "which plug-in stage" scenario to one correct answer even if the wording is unfamiliar.

Does MainOperation ever apply to me on the exam?

Only in the context of custom APIs and custom virtual table data providers — Microsoft explicitly reserves it for internal use otherwise. If an answer choice suggests registering ordinary business logic on MainOperation, it's a distractor.

More PL-400 Resources