<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>User groups and permissions | Dynatrace help</title>
    <description></description>
    <link>https://www.dynatrace.com/support/help/</link>
    <atom:link href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/user-groups-and-permissions/feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Fri, 18 Oct 2019 07:17:18 +0200</lastBuildDate>
    <pubDate>Mon, 08 Apr 2019 13:05:46 +0200</pubDate>
    <generator>Metalsmith v2.3.0</generator>
    <item>
      <title>User groups and permissions updated on Mon, 08 Apr 2019 13:05:46 +0200</title>
      <description>&lt;p&gt;You need to configure user groups in Dynatrace Managed to allow access to your monitoring environment or your Dynatrace Server.&lt;/p&gt;
&lt;h2 id=&quot;manage-groups-and-users&quot;&gt;Manage groups and users
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#manage-groups-and-users&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;A default administrator account is created during Dynatrace Managed installation. This account exists regardless of the authentication type you select (internal or LDAP). The default administrator account has cluster permissions.&lt;/p&gt;
&lt;p&gt;You can manage users and groups through Cluster Management Console by selecting &lt;strong&gt;User authentication&lt;/strong&gt; in the navigation menu.&lt;/p&gt;
&lt;h3 id=&quot;to-create-a-group&quot;&gt;To create a group
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#to-create-a-group&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Select &lt;strong&gt;User authentication &amp;gt; User groups&lt;/strong&gt; in the navigation menu.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Add new group&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;Assign permissions to the newly created group
&lt;ul&gt;
&lt;li&gt;To assign administration permissions to the group, set &lt;strong&gt;Grant global administrator permissions to this group&lt;/strong&gt; to the &lt;strong&gt;On&lt;/strong&gt; position. The group will have access rights to all environments.&lt;/li&gt;
&lt;li&gt;To assign individual access rights for each environment, enter a comma-separated list of LDAP group names that should be mapped to this user group.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;to-create-a-user&quot;&gt;To create a user
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#to-create-a-user&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Select &lt;strong&gt;User authentication &amp;gt; User accounts&lt;/strong&gt; in the navigation menu.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Add new user&lt;/strong&gt;.&lt;br&gt;
&lt;strong&gt;Note&lt;/strong&gt;: This option is available only if you are using an internal database, not LDAP.&lt;/li&gt;
&lt;/ol&gt;
&lt;h3 id=&quot;to-assign-a-user-to-groups&quot;&gt;To assign a user to groups
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#to-assign-a-user-to-groups&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;ol&gt;
&lt;li&gt;Select &lt;strong&gt;User authentication &amp;gt; User accounts&lt;/strong&gt; in the navigation menu.&lt;/li&gt;
&lt;li&gt;Select the user.&lt;/li&gt;
&lt;li&gt;Select &lt;strong&gt;Add&lt;/strong&gt; in the &lt;strong&gt;Add group assignments&lt;/strong&gt; section.&lt;br&gt;
&lt;strong&gt;Note&lt;/strong&gt;: A group cannot be assigned if there are no permissions specified for this group.&lt;/li&gt;
&lt;/ol&gt;
&lt;h2 id=&quot;permissions&quot;&gt;Permissions
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#permissions&quot;&gt;
      &lt;/span&gt;&lt;/h2&gt;
&lt;p&gt;You can assign a pre-defined set of permissions to a group. Once a group is defined, you can add users to the group. Added users inherit the permissions of the groups they are assigned to. Any group can be modified to fit your needs. You can even create new groups and assign permissions to them.&lt;/p&gt;
&lt;h3 id=&quot;cluster-permissions&quot;&gt;Cluster permissions
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#cluster-permissions&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Users assigned to groups with this permission are automatically given administrator access rights for all environments. They have access to Cluster Management Console and can manage your monitoring environments and Dynatrace Server. Users assigned to groups with this permission can also:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Add new Dynatrace Server nodes&lt;/li&gt;
&lt;li&gt;Upgrade Dynatrace Server&lt;/li&gt;
&lt;li&gt;Manage Dynatrace Managed users and user groups&lt;/li&gt;
&lt;li&gt;Install Dynatrace OneAgent into any monitoring environment&lt;/li&gt;
&lt;li&gt;Configure monitoring settings for any monitoring environment&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id=&quot;environment-permissions&quot;&gt;Environment permissions
      &lt;span class=&quot;shortlink-copy shortlink-copy-js&quot; data-clipboard-text=&quot;https://www.dynatrace.com/support/help/shortlink/managed-user-groups#environment-permissions&quot;&gt;
      &lt;/span&gt;&lt;/h3&gt;
&lt;p&gt;Dynatrace provides the following environment-based permissions:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Access environment&lt;/strong&gt;. Allows read-only access to the environment. Can&amp;apos;t change settings or install OneAgent.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Change monitoring settings&lt;/strong&gt;. Allows changing of all environment settings. Can&amp;apos;t install OneAgent.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Download &amp;amp; install OneAgent&lt;/strong&gt;. Allows download of OneAgent and installation on hosts. Can&amp;apos;t change settings.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;View logs&lt;/strong&gt;. Allows access to sensitive log file data.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;View sensitive request data&lt;/strong&gt;. Allows viewing of potentially personal data. Users that don&amp;apos;t have this permission see that the data point exists but the personal data is masked out with &lt;code&gt;*****&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Configure request capture data&lt;/strong&gt; (upcoming feature). Allows configuration of request-data capture rules. These can be used to capture elements such as HTTP headers or Post parameters for storage, filtering, and search.&lt;/li&gt;
&lt;/ul&gt;
</description>
      <pubDate>Mon, 08 Apr 2019 13:05:46 +0200</pubDate>
      <link>https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/user-groups-and-permissions/?updated=mon-08-apr-2019-13-05-46-0200</link>
      <guid isPermaLink="true">https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/users-and-groups-setup/user-groups-and-permissions/</guid>
    </item>
  </channel>
</rss>