Try it free

Upgrade management zones to IAM and segments

  • Latest Dynatrace
  • Upgrade guide
  • Published Jul 24, 2026

Configure boundaries, policies, and groups based on dt.security_context or your desired permission field. Link with your IdP, configure SSO, and invite users. Create segments that work as global filters across the platform, meeting classic management zone filtering requirements.

Why upgrade?

Replacing management zones with IAM and segments eliminates a maintenance-heavy access control model and gives teams dynamic, policy-based filtering that scales with your environment automatically.

  • Team onboarding to Latest Dynatrace: teams can start using the Latest Dynatrace platform with secure, role-based access scoped to their boundaries
  • Dynamic, low-maintenance filters: segments replace classic management zones and tags, enabling easier navigation and reducing access management overhead

What will you do?

This stage replaces classic management zones with the IAM and segment model the latest platform is built on, a one-way transition that requires careful validation before classic zones are removed.

  1. Design a pure Latest Dynatrace ABAC model: review existing RBAC setup and design IAM using policies, boundaries, and dt.security_context
  2. Create segments from Primary Grail Fields and Tags to replace classic management zone filtering
  3. Validate the new permissions model with users and decommission classic management zones

Before you begin

At a glance

  • Estimated effort: 1–4 days
  • Estimated timeline: 1–2 weeks

Prerequisites

Enrich your observability signals must be complete before starting this stage. IAM boundaries and segments rely on dt.security_context being consistently applied across all monitored entities.

Key stakeholders

RoleInvolvementResponsibility

Dynatrace Admin

Required

Primary configuration owner for boundaries, policies, and groups

IdP Owner

Recommended

Configures SSO, SAML/OIDC integration, and manages group synchronization

Application Team Leads

Recommended

Validate that segment-based filtering meets their operational needs

Security / Compliance

Optional

Reviews IAM policies against regulatory requirements

Upgrade your IAM and segments

1. Design the IAM model

Review the existing RBAC setup and design a pure Latest Dynatrace ABAC model using policies, boundaries, and dt.security_context. Boundary definitions must not reference classic management zones.

  1. Export a list of all active management zones from Dynatrace Classic settings and document their filter criteria: entity types, tags, and naming patterns.
  2. Identify which teams, dashboards, alerts, and SLOs reference each management zone. Flag complex rules that may not translate directly to segments.
  3. Map each management zone scope to the corresponding dt.security_context value defined during stage 2.
  4. Define boundaries in Account Management based on mapped dt.security_context values. Boundary definitions must not reference classic management zones.
  5. Create policies that grant the appropriate permissions per boundary.
  6. Create groups and assign them to the relevant policies and boundaries.
  7. Configure SSO, link your IdP using SAML or OIDC, and invite users to validate access.

Verify: Each team can log in and access only the data within their assigned boundary. The number of policy-based groups equals or exceeds the former number of role-based groups.

Map management zone gaps before cutover: complex classic management zone rules may not translate 1:1 to segments. Some filtering logic requires redesign rather than direct migration. Identify these before committing to a cutover timeline.

Validate enrichment coverage before this stage: IAM boundaries depend on dt.security_context being consistently applied. Gaps in enrichment leave data outside boundaries or incorrectly accessible. Validate enrichment coverage before beginning this stage.

2. Create segments to replace management zones

Build segments that replicate the filtering behavior of each classic management zone and function as global filters across the platform.

  1. For each management zone, create an equivalent segment using the enrichment attributes defined during stage 2.
  2. Configure segment filters to match the entity scope of the original management zone.
  3. Assign segments to the appropriate teams and validate that filtering behavior matches expectations.
  4. Confirm that segments work across dashboards, alerting, and other platform views.

Verify: Each team can use their segment as a global filter and see the same scoped data they previously accessed through management zone filtering.

3. Validate team access and decommission management zones

Confirm that every team can access their scoped data correctly, then remove classic management zones.

  1. Have each team validate that their boundary and segment expose the correct entities, dashboards, and alerts.
  2. Confirm that no data is missing or unexpectedly accessible outside the expected boundary.
  3. Communicate the change to affected users; switching from management zone to IAM-based access changes what users see.
  4. Archive or disable classic management zones once all teams confirm access.

Verify: High enrichment percentage across monitored entities; all teams validate access without escalations before classic management zones are removed.

Communicate the cutover to affected users: switching from management zone to IAM-based access changes what users see. Without clear communication, teams may report missing data as a platform issue. Plan a communication step before decommissioning management zones.

Stage complete when:

  • Each team can log in and access only the data within their assigned boundary
  • Each team can use their segment as a global filter and see the correct scoped data
  • Classic management zones are archived or disabled after all teams confirm access

With access boundaries, policies, and segments in place, your IAM model is configured for the latest platform. The next stage is Upgrade observability data and settings: migrate RUM applications, cloud integrations, extensions, and log ingestion to Latest Dynatrace so that all observability signals flow through Grail.

Documentation and best practices

The following resources support your work in this stage. Documentation covers platform concepts, configuration reference, and related guides; best practice cards provide implementation guidance from Dynatrace experts.

  • Identity and access management (IAM)

    Configure boundaries, policies, groups, and SSO integration in Dynatrace Account Management.

  • Upgrade from management zones to segments

    Step-by-step guide for creating segments that replace classic management zone filters.

  • Best practices for upgrading management zones to segments

    Map management zone dimensions to segments, enrich telemetry, and configure dynamic filtering that scales with your environment.

Ready for more?

When teams are validated on segment-based access and classic management zones are decommissioned, you're ready to migrate observability capabilities to the latest platform. This stage upgrades RUM, cloud integrations, log ingestion, and extensions, everything that delivers monitoring data into Latest Dynatrace.

Continue to Upgrade observability data & settings.

Related tags
Dynatrace Platform