Configure boundaries, policies, and groups based on dt.security_context or your desired permission field. Link with your IdP, configure SSO, and invite users. Create segments that work as global filters across the platform, meeting classic management zone filtering requirements.
Replacing management zones with IAM and segments eliminates a maintenance-heavy access control model and gives teams dynamic, policy-based filtering that scales with your environment automatically.
This stage replaces classic management zones with the IAM and segment model the latest platform is built on, a one-way transition that requires careful validation before classic zones are removed.
dt.security_contextEnrich your observability signals must be complete before starting this stage. IAM boundaries and segments rely on dt.security_context being consistently applied across all monitored entities.
| Role | Involvement | Responsibility |
|---|---|---|
Dynatrace Admin | Required | Primary configuration owner for boundaries, policies, and groups |
IdP Owner | Recommended | Configures SSO, SAML/OIDC integration, and manages group synchronization |
Application Team Leads | Recommended | Validate that segment-based filtering meets their operational needs |
Security / Compliance | Optional | Reviews IAM policies against regulatory requirements |
Review the existing RBAC setup and design a pure Latest Dynatrace ABAC model using policies, boundaries, and dt.security_context. Boundary definitions must not reference classic management zones.
dt.security_context value defined during stage 2.dt.security_context values. Boundary definitions must not reference classic management zones.Verify: Each team can log in and access only the data within their assigned boundary. The number of policy-based groups equals or exceeds the former number of role-based groups.
Map management zone gaps before cutover: complex classic management zone rules may not translate 1:1 to segments. Some filtering logic requires redesign rather than direct migration. Identify these before committing to a cutover timeline.
Validate enrichment coverage before this stage: IAM boundaries depend on dt.security_context being consistently applied. Gaps in enrichment leave data outside boundaries or incorrectly accessible. Validate enrichment coverage before beginning this stage.
Build segments that replicate the filtering behavior of each classic management zone and function as global filters across the platform.
Verify: Each team can use their segment as a global filter and see the same scoped data they previously accessed through management zone filtering.
Confirm that every team can access their scoped data correctly, then remove classic management zones.
Verify: High enrichment percentage across monitored entities; all teams validate access without escalations before classic management zones are removed.
Communicate the cutover to affected users: switching from management zone to IAM-based access changes what users see. Without clear communication, teams may report missing data as a platform issue. Plan a communication step before decommissioning management zones.
Stage complete when:
With access boundaries, policies, and segments in place, your IAM model is configured for the latest platform. The next stage is Upgrade observability data and settings: migrate RUM applications, cloud integrations, extensions, and log ingestion to Latest Dynatrace so that all observability signals flow through Grail.
The following resources support your work in this stage. Documentation covers platform concepts, configuration reference, and related guides; best practice cards provide implementation guidance from Dynatrace experts.
Identity and access management (IAM)
Configure boundaries, policies, groups, and SSO integration in Dynatrace Account Management.
Upgrade from management zones to segments
Step-by-step guide for creating segments that replace classic management zone filters.
Best practices for upgrading management zones to segments
Map management zone dimensions to segments, enrich telemetry, and configure dynamic filtering that scales with your environment.
When teams are validated on segment-based access and classic management zones are decommissioned, you're ready to migrate observability capabilities to the latest platform. This stage upgrades RUM, cloud integrations, log ingestion, and extensions, everything that delivers monitoring data into Latest Dynatrace.
Continue to Upgrade observability data & settings.