Manage group permissions with IAM policies

Use these procedures in the Dynatrace web UI to manage group permissions with IAM policies.

API alternative

To instead use the API to manage group permissions with IAM policies, go to https://iam.dynatrace.com/swagger/

List all policies bound to a group

  1. Go to the Group management page:
    • Dynatrace SaaS: in the user menu, go to Account settings and select Identity management > Group management.
    • Dynatrace Managed: in the Cluster Management Console, select User authentication > User groups.
  2. Find the group in the list and select the pen icon to Edit the group.
  3. In the Environment permissions section, expand the environment for which you want to edit group permissions.
  4. Select the Policies tab.
  5. Review the Bound policies list under the search bar. Because these policies are bound to the group, they apply to every account that is a member of the group.

Bind a policy to a group

To bind (add) a policy to a group

  1. On the Policies tab, filter for and select the policy in the Filter by box.

    • You can select multiple policies and bind them all at once.
  2. Select Bind to bind the selected policies to the group.

    • The selected policies are added to the Bound policies list under the filter bar.
    • If you change your mind about a policy, select Unbind to remove it from the list.
    • The Save button is now displayed, but you can still add and remove policies before you save your changes.
  3. When you have assembled the exact list of policies you want to bind to the selected group in the selected environment, select Save.

    In Dynatrace Managed, policy changes may take a couple of minutes to take effect after you select Save.

Unbind a policy from a group

To unbind (remove) a policy from a group

  1. On the Policies tab, find the policy in the list under the search bar.

  2. Select Unbind for that policy.

    • The selected policy is removed from the Bound policies list under the filter bar.
    • The Save button is now displayed, but you can wait until you unbind multiple policies before you save your changes.
  3. When you have assembled the exact list of policies you want to unbind from the selected group in the selected environment, select Save.

    In Dynatrace Managed, policy changes may take a couple of minutes to take effect after you select Save.

Manage policies

To manage IAM policies, go to the Policy management page:

  • Dynatrace SaaS: in the user menu, go to Account settings and select Identity management > Policy management.
  • Dynatrace Managed: in the Cluster Management Console, select User authentication > Policy management.

For details, see Manage IAM policies.