recommended
Dynatrace version 1.252+
Starting with Dynatrace version 1.252, you can manage role-based access using policies. For more information, see Migrate role-based permissions to Dynatrace IAM policies.
Go to Account Management—see Account Management for more information.
Dynatrace provides the following account-level permissions.
Dynatrace provides the following environment-level permissions. Select all that apply:
View environment: Allows read-only access to the environment. You cannot change settings or install OneAgent with this permission alone.
View environment permission is required for any of the other environment permissions, so View environment is automatically selected for the environment when you select any other environment permission.
*****
). Also allows manually triggering memory dumps.Install OneAgent: Allows download of OneAgent and installation on hosts. To change/edit settings, you must provide the Manage monitoring settings permission.
Manage monitoring settings: Allows changing of all environment settings. To install OneAgent, you must provide the Install OneAgent permission.
Manage capturing of sensitive request data: Allows configuration of request-attribute capture rules. These can be used to capture elements such as HTTP headers or Post parameters for storage, filtering, and search. Also allows manually triggering memory dumps.
Manage security problems: Allows viewing and management of vulnerabilities reported by Dynatrace Application Security.
View security problems: Allows viewing (but not management) of vulnerabilities reported by Dynatrace Application Security.
For details on Application Security permissions, see Fine-tune permissions.
Dynatrace provides the following management-zone-level permissions. Select all that apply:
View environment: Allows read-only access to the entities within the management zone. To change/edit settings, you must provide the Change monitoring settings permission.
View environment permission is required for any of the other management zone permissions, so View environment is automatically selected for the management zone when you select any other management zone permission.
*****
)—see also Environment permissions above.Replay session data with masking: Allows replay of recorded user sessions with playback masking rules applied at the time of replay. Note that any data masked during recording is never captured and, therefore, always masked during replay.
Replay session data without masking: Allows replay of recorded user sessions without playback masking rules applied. Note that any data masked during recording is always masked during replay.
For Session Replay permissions to work within a management zone, the user also needs to have access to the requisite applications.
For details on management zones, see Management zones.
Manage security problems: Allows viewing and management of vulnerabilities reported by Dynatrace Application Security.
View security problems: Allows viewing (but not management) of vulnerabilities reported by Dynatrace Application Security.
For details on Application Security permissions, see Fine-tune permissions.
When you provide any permission other than View environment at the environment level, View environment is automatically enabled as well for the environment. Likewise, when you provide any permission other than View environment at the management-zone level, View environment is automatically enabled for the management zone.
Management zones are designed to provide targeted and limited access to certain entities within an environment. If you wish to provide a permission to users accessing a management zone, we recommend that you use the management-zone-level permissions. Any permission you provide at the environment level supersedes and adds to those at the management-zone level. In other words, management-zone permissions cannot be used to limit permissions already provided at the environment level.
Take the example of a management zone containing three hosts out of five total hosts in an environment. If you grant the View logs permission to the management zone, viewers can see the Logs tab with information for the three hosts in the management zone. However, if you remove the same permission at the management-zone level and provide it at the environment level, users will be able to: