Try it free

Best practices for upgrading to Latest Dynatrace

  • Latest Dynatrace
  • Upgrade guide
  • Published Jul 24, 2026

Upgrading from Dynatrace Classic to the latest platform is a complex, team-coordinated process that spans multiple capability areas. The best practices in this guide are drawn from upgrade engagements across enterprise accounts and validated by Dynatrace's Center of Excellence (CoE) and Customer Success teams.

This guide presents a recommended sequence—not a mandatory one. Not every stage applies to every account: some stages depend on capabilities or integrations tied to specific licensing tiers, and some may be out of scope depending on your existing configuration. Use this as a reference to plan your upgrade, skip stages that don't apply, and revisit deferred stages as your licensing or requirements change.

Why upgrade?

Dynatrace Classic is built on static, precomputed configurations: management zones, metric selectors, and notification channels that require manual upkeep as your environment scales. The latest Dynatrace replaces this model with a dynamic, query-based platform backed by Grail.

  • Dynamic, policy-based access control: IAM boundaries and segments scope access automatically based on enrichment metadata, eliminating the manual upkeep required by classic management zones as your team or environment grows.
  • Query-based observability with Grail: metrics, logs, and traces are queryable on-the-fly with DQL, enabling precise ad-hoc analysis not possible with precomputed classic metrics and fixed dimensions.
  • Event-driven alerting with Workflows: replace static notification channels with conditional, orchestrated workflows that support branching logic, real-time event responses, and native integrations with ServiceNow, PagerDuty, and other platforms.
  • Unified entity model with Smartscape 2.0: entity relationships across all observability signals are unified, enabling consistent DQL-based topology analysis across dashboards, alerts, and workflows.
  • Granular OAuth-based API access: replace broad-scope classic API tokens with OAuth clients scoped to the minimum permissions each integration requires, reducing attack surface and improving auditability.

What will you do?

The upgrade moves through 11 stages. The first two establish the foundation before any capability migration begins; the remaining stages progressively migrate capabilities and configurations until your environment is fully running on Latest Dynatrace.

StageDescription

Scope your upgrade to Latest Dynatrace

Inventory your Dynatrace Classic configuration, agree on what gets migrated, retired, or deferred, and get stakeholder sign-off before any technical work begins.

Enrich your observability signals

Apply the metadata that access boundaries, segments, and cost allocation all depend on. Validate coverage before proceeding; insufficient enrichment affects all downstream stages.

Upgrade management zones to IAM and segments

Replace classic management zones with IAM boundaries and dynamic segments scoped to dt.security_context.

Upgrade observability data and settings

Migrate RUM, cloud integrations, extensions, and log ingestion to the latest platform.

Partition your Grail data

Assess signal volumes and configure bucket routing to optimize query performance and enforce retention policies per your compliance requirements.

Upgrade configurations and settings

Migrate service naming, metrics, SLOs, and processing rules. Complete before starting stages 7 and 8.

Upgrade classic dashboards

Migrate actively used classic dashboards using the built-in converter, then rebuild unconverted tiles and management zone filters manually. Runs in parallel with stage 8.

Upgrade metric alerting and maintenance windows

Convert classic metric alerts, recreate entity-selector-based alerts with DQL, and upgrade maintenance windows. Runs in parallel with stage 7.

Upgrade team-based and global alerting

Migrate problem notifications, security notifications, and enterprise ITSM integrations to event-driven Workflows. Requires stages 7 and 8 to be complete.

Upgrade remaining entities and metrics

Update DQL queries in dashboards, alerts, and workflows to reference Smartscape 2.0 entity types.

Upgrade your API integrations and tokens

Audit classic API usage, create OAuth clients with granular scopes, and migrate integrations to Latest Dynatrace endpoints.

Before you begin

Prerequisites

  • A DPS license and an active Dynatrace environment with access to both classic and latest Dynatrace capabilities
  • A dedicated project team with at least one Dynatrace Admin who can configure environment-level settings across all upgrade stages
  • A completed classic configuration inventory (produced during the Prepare stage, required before starting the Upgrade Core stage)

Stakeholder reference

The following roles contribute to the upgrade journey across different stages. Refer to each stage guide for the specific stakeholders required at that step.

StakeholderRole across the upgrade

Dynatrace Admin

Primary point of contact for all technical configuration, environment access, and deployment coordination. Present in every stage.

Application Team Leads

Validate that access boundaries, dashboards, alerts, and SLOs meet their team's operational needs. Stages 3–11.

Project Sponsor

Approves scope, confirms out-of-scope decisions, and signs off on success criteria. Stage 1.

Data Owner

Owns the source-of-truth for dimension mappings used in enrichment. Stage 2.

IdP Owner

Configures SSO, SAML/OIDC integration, and manages group synchronization. Stage 3.

DevOps / Platform Eng.

Owns CI/CD pipelines, automation scripts, cloud integrations, and extensions. Stages 4 and 11.

Cloud Ops

Needed for cloud connection upgrades and resource discovery validation. Stage 4.

SRE / Observability Eng.

Owns SLO definitions, calculated metric conversions, and DQL query migrations. Stages 6–11.

Dashboard Owners

Confirm converted tiles, filters, and variables match their original intent. Stage 7.

IT Operations

Own enterprise ITSM integrations (ServiceNow, PagerDuty) and validate bidirectional workflow behavior. Stage 9.

Security / Compliance

Reviews IAM policies, validates RVA rule coverage, defines retention mandates, and approves OAuth client scopes. Multiple stages.

How to upgrade

The upgrade happens across 11 sequential stages. The first two establish the foundation—scope and enrichment—before any capability migration begins. The remaining stages migrate access control, observability capabilities, data organization, and configurations. Most enterprise environments complete the full upgrade in 6–12 months.

1. Define your upgrade scope

Before any technical work begins, agree on scope: which teams, applications, and classic assets are in scope, what gets deferred, and what success looks like.

For details, see Scope your upgrade to Latest Dynatrace.

2. Enrich your observability signals

With scope defined, enrich all monitored signals with the metadata that IAM, segments, and cost allocation depend on. This stage is iterative: validate coverage, fix gaps, re-validate.

Apply dt.security_context, dt.cost.costcenter, dt.cost.product, and primary_tags.* across all monitored signals. Enrichment coverage must meet the agreed threshold before starting stage 3.

For details, see Enrich your observability signals.

Insufficient enrichment at stage 2 results in poorly configured access control, segmentation, and cost allocation across all downstream stages. Validate coverage before proceeding.

With enrichment in place, you can then configure access boundaries and migrate observability capabilities.

3. Configure access control

Configure access boundaries, policies, and groups based on dt.security_context. Replace classic management zones with dynamic segments as global filters across the platform.

For details, see Upgrade management zones to IAM and segments.

4. Upgrade your observability capabilities

Migrate RUM, cloud integrations, classic log settings, and extensions to Latest Dynatrace. Route log ingestion through OpenPipeline and Grail.

For details, see Upgrade observability data and settings.

5. Organize your Grail data

After observability capabilities are upgraded, assess signal volumes and configure bucket routing if needed. Required before starting stage 6 for high-volume environments.

Assess log and span volumes, design a bucket strategy, and configure OpenPipeline routing to optimize query performance and enforce retention policies.

For details, see Partition your Grail data.

With your environment enriched, capabilities upgraded, and data organized, your environment will then be ready for the configuration upgrade phase, in which teams can begin migrating their classic configurations to Latest Dynatrace.

6. Upgrade configurations & settings

Migrate service naming rules to OpenPipeline, upgrade service detection, replace calculated metrics with DQL-based Grail equivalents, migrate processing rules, rebuild SLOs, and upgrade RVA monitoring rules.

For details, see Upgrade configurations and settings.

7. Upgrade classic dashboards

Migrate actively used classic dashboards using the built-in converter, then rebuild unconverted tiles and management zone filters manually.

This stage runs in parallel with stage 8. Both must complete before starting stage 9.

For details, see Upgrade classic dashboards.

8. Upgrade metric alerting and maintenance windows

Convert classic metric alerts using the built-in tooling, recreate entity-selector-based alerts with DQL, and upgrade maintenance windows.

This stage runs in parallel with stage 7. Both must complete before starting stage 9.

For details, see Upgrade metric alerting and maintenance windows.

9. Upgrade team-based and global alerting

Migrate problem notifications, security notifications, and enterprise integrations (ServiceNow, PagerDuty) to event-driven workflow-based delivery.

For details, see Upgrade team-based and global alerting.

10. Upgrade remaining entities and metrics

Update DQL queries in dashboards, alerts, and workflows to reference Smartscape 2.0 entity types and relationships after the dashboard and alerting upgrades.

For details, see Upgrade remaining entities and metrics.

11. Upgrade your API integrations and tokens

Audit classic API usage, create OAuth clients with granular scopes, and migrate CI/CD pipelines and third-party integrations to Latest Dynatrace endpoints.

For details, see Upgrade your API integrations and tokens.

After the upgrade

Completing all 11 stages means your environment is fully running on Latest Dynatrace. Classic configurations have been migrated or retired, access is governed by IAM boundaries and segments, and all observability signals flow through Grail.

The final step is attribution. The enrichment attributes and data buckets you configured in the early phases now power cost allocation; use them to show each team and cost center exactly what they're consuming.

  • Review DPS consumption per team using cost allocation dashboards
  • Validate that dt.cost.costcenter or equivalent attributes are correctly applied and bucketed
  • Share consumption reports with team leads and adjust budgets as needed

With cost attribution in place, your upgrade is complete. Use the Wayfinder overview as an ongoing reference if teams onboard later or if deferred stages are revisited.

Related tags
Dynatrace Platform