Use these procedures in the Dynatrace web UI to manage Dynatrace IAM policies.
To instead use the API to manage IAM policies, go to Cluster API v2.
To list configured IAM policies
In the Cluster Management Console, go to User authentication > Policy management.
Review the table of all existing policies that you can bind to user groups.
global, cluster, or environmentTo let you use policies right away, Dynatrace IAM is shipped with built-in global policies.
DynatraceTo create a policy
In the Cluster Management Console, go to User authentication > Policy management.
Select Add policy.
Enter the following information.
For a complete and up-to-date list of Dynatrace services that support permission management via IAM policies, see IAM policy reference.
To edit an existing policy
To delete a policy
In the Cluster Management Console, go to User authentication > Policy management.
Find the policy you want to delete.
You can filter and sort the table.
Select the Edit button for the policy.
Select Delete policy.
The change takes effect in a few minutes.
To change the delay, modify property policyRefreshIntervalSeconds in the iam section of the config file.
To copy an existing policy
To apply a policy to a group, you need to bind the policy to the group. For details on managing group permissions with IAM, see Working with policies.