<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Manage users and groups with OpenID | Dynatrace help</title>
    <description></description>
    <link>https://www.dynatrace.com/support/help/</link>
    <atom:link href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-openid/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Fri, 18 Oct 2019 07:17:18 +0200</lastBuildDate>
    <pubDate>Mon, 08 Apr 2019 13:05:46 +0200</pubDate>
    <generator>Metalsmith v2.3.0</generator>
    <item>
      <title>Manage users and groups with OpenID updated on Mon, 08 Apr 2019 13:05:46 +0200</title>
      <description>&lt;p&gt;Dynatrace Managed supports integration with &lt;a href=&quot;http://openid.net/what-is-openid/&quot;&gt;OpenID&lt;/a&gt; as an SSO IdP (Single Sign-On Identity Provider) for the management of users and groups. We currently support standard claims (email, profile, address) as defined in the &lt;a href=&quot;https://openid.net/specs/openid-connect-core-1_0.html#StandardClaims&quot;&gt;OpenID Connect Core 1.0 specification&lt;/a&gt;. The &lt;code&gt;redirect_uri&lt;/code&gt; used for authentication is set to the Dynatrace Managed Web UI URL that&amp;apos;s configured in your Cluster Management Console. Note that this URI must also be configured in your OpenID-provider client.&lt;/p&gt;
&lt;h2 id=&quot;set-up-openid-integration&quot;&gt;Set up OpenID integration
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-openid#set-up-openid-integration&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;ol&gt;
&lt;li&gt;From the Cluster Management Console menu, select &lt;strong&gt;User authentication&lt;/strong&gt; &amp;gt; &lt;strong&gt;Single sign-on settings&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;From the list, select &lt;strong&gt;OpenID Connect&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;To change the login page, you must prove that your SSO mechanism is actually working by signing out and logging in using SSO. The standard page will be shown as a fallback if something goes wrong.&lt;/li&gt;
&lt;li&gt;Enter the &lt;strong&gt;Client ID&lt;/strong&gt; and &lt;strong&gt;Client Secret&lt;/strong&gt; of the client from the IdP that will be used for authentication.&lt;/li&gt;
&lt;li&gt;In the &lt;strong&gt;Server discovery endpoint&lt;/strong&gt; text field, type in the Open ID configuration URL provided by the IdP and click &lt;strong&gt;Import Configuration&lt;/strong&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;group-assignment-configuration&quot;&gt;Group assignment configuration
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-openid#group-assignment-configuration&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;Each Dynatrace Managed user must be assigned to at least one user group, with at least one associated &lt;a href=&quot;https://www.dynatrace.com/support/help/reference/dynatrace-concepts/what-is-a-monitoring-environment/&quot;&gt;monitoring environment&lt;/a&gt;. Without such a mapping, the user can&amp;apos;t sign in to Dynatrace Managed and will receive an error message stating that no environment has been found.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Assign users to groups based on UserInfo response attribute&lt;/strong&gt; switch determines how you manage user-group assignments:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Manually: Set the switch to the &lt;strong&gt;off&lt;/strong&gt; position if you want to make user-group assignments manually from within Dynatrace Managed. In this case, Dynatrace Managed ignores the list of groups sent in your IdP&amp;apos;s authentication response.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Automatically: Set the switch to the &lt;strong&gt;on&lt;/strong&gt; position and enter the group name in the &lt;strong&gt;User groups&lt;/strong&gt; attribute field if you want to handle user-group assignment automatically. In this case, any assignments made within Dynatrace Managed are overwritten by the list of groups sent in your IdP&amp;apos;s authentication response. You can add a custom user groups separator to separate user groups.&lt;/p&gt;
&lt;p&gt;
&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
</description>
      <pubDate>Mon, 08 Apr 2019 13:05:46 +0200</pubDate>
      <link>https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-openid/?updated=mon-08-apr-2019-13-05-46-0200</link>
      <guid isPermaLink="true">https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-openid/</guid>
    </item>
  </channel>
</rss>