<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Manage users and groups with SAML in Dynatrace Managed | Dynatrace help</title>
    <description></description>
    <link>https://www.dynatrace.com/support/help/</link>
    <atom:link href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-saml/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Fri, 18 Oct 2019 07:17:18 +0200</lastBuildDate>
    <pubDate>Wed, 24 Apr 2019 21:34:37 +0200</pubDate>
    <generator>Metalsmith v2.3.0</generator>
    <item>
      <title>Manage users and groups with SAML in Dynatrace Managed updated on Wed, 24 Apr 2019 21:34:37 +0200</title>
      <description>&lt;p&gt;Dynatrace Managed supports integration with SAML 2.0 as an SSO IdP (Single Sign-On Identity Provider) for the management of users and groups. SAML can use either &lt;code&gt;HTTP POST&lt;/code&gt; (preferred) or &lt;code&gt;HTTP Redirect&lt;/code&gt; bindings. When both are present, &lt;code&gt;HTTP POST&lt;/code&gt; is used.&lt;/p&gt;
&lt;h2 id=&quot;set-up-saml-20-integration&quot;&gt;Set up SAML 2.0 integration
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#set-up-saml-20-integration&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;This procedure requires configuration in Dynatrace Managed and at your IdP.&lt;/p&gt;
&lt;h3 id=&quot;in-dynatrace-managed&quot;&gt;In Dynatrace Managed
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#in-dynatrace-managed&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;In the Dynatrace Managed Cluster Management Console&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Select &lt;strong&gt;User authentication &amp;gt; Single sign-on settings&lt;/strong&gt;.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-166example-single-sign-on-settings&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-166example-single-sign-on-settings&quot;&gt;Example `Single sign-on settings`&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/image-2293-3e9c99837a.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Under &lt;strong&gt;Select single sign-on technology&lt;/strong&gt;, select &lt;strong&gt;SAML 2.0&lt;/strong&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click &lt;strong&gt;Download SP metadata&lt;/strong&gt; to download (to file &lt;code&gt;sp.xml&lt;/code&gt;) the SAML metadata you need to provide to your SP.&lt;br&gt;
The &lt;strong&gt;XML metadata of a SAML 2.0 Service Provider&lt;/strong&gt; box displays the metadata.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;on-your-identity-provider-server-idp&quot;&gt;On your Identity Provider server (IdP)
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#on-your-identity-provider-server-idp&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;callout information&quot;&gt;
&lt;p&gt;Refer to your IdP documentation for details on these steps.&lt;/p&gt;

&lt;/div&gt;

&lt;p&gt;At your IdP server&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Use the &lt;code&gt;sp.xml&lt;/code&gt; metadata file you downloaded earlier to configure Dynatrace Managed as a Service Provider (SP).&lt;/li&gt;
&lt;li&gt;Download the completed configuration metafile from your IdP server.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;in-dynatrace-managed-1&quot;&gt;In Dynatrace Managed
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#in-dynatrace-managed-1&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Back in the Dynatrace Managed Cluster Management Console&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Return to the &lt;strong&gt;Single sign-on settings&lt;/strong&gt; page to continue where you left off.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-167example-single-sign-on-settings&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-167example-single-sign-on-settings&quot;&gt;Example `Single sign-on settings`&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/image-2293-3e9c99837a.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Click the &lt;strong&gt;Select file&lt;/strong&gt; button and upload your IdP configuration metafile to Dynatrace Managed.&lt;br&gt;
The &lt;strong&gt;XML metadata of a SAML 2.0 Identity Provider&lt;/strong&gt; box displays the metadata.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Under &lt;strong&gt;User attributes based on SAML 2.0 response attributes&lt;/strong&gt;, enter the user attributes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;First name attribute&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Last name attribute&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Email attribute&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;group-assignment-configuration&quot;&gt;Group assignment configuration
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#group-assignment-configuration&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;Each Dynatrace Managed user must be assigned to at least one user group, with at least one associated &lt;a href=&quot;https://www.dynatrace.com/support/help/reference/dynatrace-concepts/what-is-a-monitoring-environment/&quot;&gt;monitoring environment&lt;/a&gt;. Without such a mapping, the user can&amp;apos;t sign in to Dynatrace Managed and will instead receive an error message stating that no environment has been found.&lt;/p&gt;
&lt;p&gt;The &lt;strong&gt;Assign users to groups based on SAML 2.0 response attribute&lt;/strong&gt; switch determines how you manage user-group assignments:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Manually: Set the switch to the &lt;strong&gt;off&lt;/strong&gt; position if you want to make user-group assignments manually from within Dynatrace Managed. In this case, Dynatrace Managed ignores the list of groups sent in your IdP&amp;apos;s authentication response.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Automatically: Turn on the toggle and enter the group name in the &lt;strong&gt;User group attribute&lt;/strong&gt; field if you want to handle user-group assignment automatically. In this case, any assignments made within Dynatrace Managed are overwritten by the list of groups sent in your IdP&amp;apos;s authentication response, such as&lt;/p&gt;
&lt;pre&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;lt;Attribute Name=&amp;quot;gr&amp;quot;&amp;gt;  
    &amp;lt;AttributeValue&amp;gt;Admins&amp;lt;/AttributeValue&amp;gt;  
    &amp;lt;AttributeValue&amp;gt;Users&amp;lt;/AttributeValue&amp;gt;  
&amp;lt;/Attribute&amp;gt;  
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;which would assign the user to the &lt;code&gt;Admins&lt;/code&gt; and &lt;code&gt;Users&lt;/code&gt; groups.&lt;/p&gt;
&lt;div class=&quot;callout information&quot;&gt;
&lt;ul&gt;
&lt;li&gt;If the value of the user group attribute in the SAML response contains commas, Dynatrace recognizes it as a comma-separated list of user groups and assigns the user to each group in the list. For example&lt;pre&gt;&lt;code class=&quot;language-text&quot;&gt;&amp;lt;Attribute Name=&amp;quot;gr&amp;quot;&amp;gt;
        &amp;lt;AttributeValue&amp;gt;Admins,Users&amp;lt;/AttributeValue&amp;gt;
&amp;lt;/Attribute&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
would assign the user to the &lt;code&gt;Admins&lt;/code&gt; and &lt;code&gt;Users&lt;/code&gt; groups.&lt;/li&gt;
&lt;li&gt;Make sure group names exactly match existing Dynatrace user group names (case-sensitive, no extra spaces). For example, &lt;code&gt;Admins&lt;/code&gt; and &lt;code&gt;admins&lt;/code&gt; would be two different groups.&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;

&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id=&quot;adfs-configuration&quot;&gt;ADFS configuration
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#adfs-configuration&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;If you choose to integrate Dynatrace Managed with Active Directory Federation Services (ADFS), perform the following steps on the ADFS side and then in Dynatrace Managed.&lt;/p&gt;
&lt;h3 id=&quot;configuration-on-the-adfs-side&quot;&gt;Configuration on the ADFS side
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#configuration-on-the-adfs-side&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;div class=&quot;step&quot;&gt;
&lt;p&gt;Use the &lt;strong&gt;Add Relying Party Trust Wizard&lt;/strong&gt; to add a new relying party trust using Dynatrace SP metadata configuration.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-168add-relying-party-trust-wizard-example&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-168add-relying-party-trust-wizard-example&quot;&gt;Add Relying Party Trust Wizard example&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs1-896-44cc5748c9.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;

&lt;/div&gt;
&lt;div class=&quot;step&quot;&gt;
&lt;p&gt;On the &lt;strong&gt;Advanced&lt;/strong&gt; tab, set &lt;strong&gt;Secure hash algorithm&lt;/strong&gt; to &lt;code&gt;SHA-1&lt;/code&gt;.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-169advanced-tab-example&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-169advanced-tab-example&quot;&gt;Advanced tab example&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs2-495-a9ece8bd6b.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;

&lt;/div&gt;
&lt;div class=&quot;step&quot;&gt;
&lt;p&gt;Add a claim issuance policy to the added relying party trust.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-170edit-claim-issuance-policy-example&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-170edit-claim-issuance-policy-example&quot;&gt;Edit Claim Issuance Policy example&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs3-300-1a619dccbe.png&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;

&lt;/div&gt;
&lt;div class=&quot;step&quot;&gt;
&lt;p&gt;Define a rule to send LDAP attributes as claims.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-171example-rule-send-ldap-attributes-as-claims&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-171example-rule-send-ldap-attributes-as-claims&quot;&gt;Example rule: send LDAP attributes as claims&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs4-683-8d48924f8c.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;

&lt;/div&gt;
&lt;div class=&quot;step&quot;&gt;
&lt;p&gt;Define rules to transform LDAP attributes to &lt;code&gt;Name ID&lt;/code&gt; (create a rule appropriate to your needs).&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Example of a rule to transform the LDAP &lt;code&gt;login&lt;/code&gt; attribute to &lt;code&gt;Name ID&lt;/code&gt;.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-172example-rule-ldap-login-attribute-to-name-id&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-172example-rule-ldap-login-attribute-to-name-id&quot;&gt;Example rule: LDAP `login` attribute to `Name ID`&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs5-685-877105f0f1.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Example of a rule to transform the LDAP &lt;code&gt;email&lt;/code&gt; attribute to &lt;code&gt;Name ID&lt;/code&gt;.&lt;/p&gt;
&lt;section class=&quot;expandable expandable--separated&quot; id=&quot;expand-173example-rule-ldap-email-attribute-to-name-id&quot;&gt;
&lt;a class=&quot;expandable__trigger&quot; href=&quot;#expand-173example-rule-ldap-email-attribute-to-name-id&quot;&gt;Example rule: LDAP `email` attribute to `Name ID`&lt;/a&gt;
&lt;article class=&quot;expandable__content&quot;&gt;&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs6-680-e9f233c985.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
&lt;/article&gt;
&lt;/section&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;/div&gt;
&lt;h3 id=&quot;configuration-on-the-dynatrace-managed-side&quot;&gt;Configuration on the Dynatrace Managed side
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-saml#configuration-on-the-dynatrace-managed-side&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;On the Dynatrace Managed &lt;strong&gt;Single sign-on settings&lt;/strong&gt; page, set the &lt;strong&gt;User group attribute&lt;/strong&gt; appropriately.&lt;/p&gt;
&lt;p&gt;&lt;img src=&quot;https://dt-cdn.net/images/adfs7-937-6490c2d4eb.jpg&quot; alt=&quot;&quot;&gt;&lt;/p&gt;
</description>
      <pubDate>Wed, 24 Apr 2019 21:34:37 +0200</pubDate>
      <link>https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-saml/?updated=wed-24-apr-2019-21-34-37-0200</link>
      <guid isPermaLink="true">https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/manage-users-and-groups-with-saml/</guid>
    </item>
  </channel>
</rss>