Migrate from management zones to security contexts for Synthetic monitors
Latest Dynatrace
How-to guide
Published Sep 01, 2026
You can migrate the names of the management zones to which Synthetic monitors belong so they become security context values.
The migration applies to Synthetic monitors only and does not affect other entity types, management zone definitions, or IAM policies.
The migration can be re-run at any time from the same entry point. Running it again applies the selected mode to the current state of your monitors.
Updating management zones or monitors after the migration does not automatically update security contexts. Re-run the migration manually if needed.
Security contexts are used with IAM policies to control which monitors a user or a group can access. If your environment uses management zones to organize Synthetic monitors, you can use this migration to carry those organizational boundaries over to security contexts without manually editing each monitor.
A monitor can belong to multiple management zones. Each management zone has one name, and each name is migrated as a separate security context value for that monitor.
Prerequisites
You need administrative access to the Dynatrace environment. The migration is available to users with Classic administrator permissions (environment:roles:manage-settings).
Note that each monitor supports a maximum of 10 security contexts. Existing security context values may be modified or removed depending on the migration mode you choose.
Configure IAM policies with the synthetic:dt.security_context condition so you can use security contexts for access control after the migration. For details, see Access control.
Migrate management zone names to security contexts
Go to Synthetic.
In the toolbar, select .
Select Set Security contexts for synthetic monitors.
Select a migration mode.
DefaultSecurity context priority: Existing security contexts are preserved and fill slots first. Remaining slots (up to the 10-context limit) are filled with management zone names. If the monitor already has 10 contexts, no management zone names are added. For example, if a monitor has eight existing security contexts and belongs to three management zones, all eight security contexts are kept, two management zone names fill the remaining slots, and one management zone name is not added. Best for environments where security contexts have already been partially configured and you want to add management zone names without losing existing values. This is the safest option and is selected by default.
Management zone priority: Management zone names take priority. Up to 10 management zone names are set as security contexts, removing existing ones if needed to stay within the limit. For example, if a monitor has eight existing security contexts and belongs to three management zones, the three management zone names are set first, seven of the existing security contexts fill the remaining slots, and one existing security context is removed to stay within the 10-context limit. Best for environments where management zones are the primary source of truth and existing security context values should be replaced by management zone names.
Replace all: Removes existing security contexts and sets up to 10 management zone names as security contexts. Best for a clean start—use this when you want the monitors' security contexts to reflect only their management zone membership, with no carry-over from previous configuration.