<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Create User Group with Management Zone level permissions in Dynatrace API</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163399#M1180</link>
    <description>&lt;P&gt;No worries. Let me rephrase:&lt;/P&gt;
&lt;P&gt;1. &lt;STRONG&gt;GET/groups/managementZones/&amp;lt;groupId&amp;gt;&lt;/STRONG&gt; returns only management zones permissions for a given group. Should be same as in UI in "Management Zones" permission section.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;&lt;STRONG&gt;GET&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;/groups/&amp;lt;groupId&amp;gt;&lt;/STRONG&gt; returns only environment level permissions for a given group. Should be same as in UI in "Environment Permissions" section for a group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the relation to you example:&lt;/P&gt;
&lt;P&gt;Group "test" allows to access:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Environment: "0d267653-6cb1-429f-a5bb-a04afb247e18" (viewer + manage settings)&lt;/LI&gt;
&lt;LI&gt;Environment: "9fe2a41e-b402-4a47-b577-9fa64cadd69c" (viewer)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and additionally to management zones:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Environment: "19000021-de09-4ea6-8076-81c0163c9c7f"
&lt;UL&gt;
&lt;LI&gt;MZ id "3477049003423719658" (sensitive, viewer, log viewer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Environment: "0d267653-6cb1-429f-a5bb-a04afb247e18"&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;MZ id "1213888254333099543" (viewer, session replay)&lt;/LI&gt;
&lt;LI&gt;MZ id "-3471389981007631349"&amp;nbsp;(sensitive, viewer, log viewer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Environment: "9fe2a41e-b402-4a47-b577-9fa64cadd69c"
&lt;UL&gt;
&lt;LI&gt;none&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope if you look this way, you see what's expected. For example for the environment "0d267653-6cb1-429f-a5bb-a04afb247e18" group allows to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- viewer (access) to all management zones (env level perm)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- manage settings to all management zones (env level perm)&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; session replay only for MZ "1213888254333099543"&lt;/P&gt;
&lt;P&gt;- view sensitive data for MZ "-3471389981007631349"&lt;/P&gt;
&lt;P&gt;- log viewer for "-3471389981007631349"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 25 Mar 2021 11:52:32 GMT</pubDate>
    <dc:creator>Radoslaw_Szulgo</dc:creator>
    <dc:date>2021-03-25T11:52:32Z</dc:date>
    <item>
      <title>Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163263#M1173</link>
      <description>&lt;P&gt;Hi everybody,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope someone here can help me here: I would like to create User Groups with permissions just for certain Management Zones in Environments, but in Dynatrace Help for Cluster api v1 (&lt;A href="https://www.dynatrace.com/support/help/setup-and-configuration/dynatrace-managed/cluster-api/cluster-api-v1/" target="_blank" rel="noopener"&gt;Cluster API v1 | Dynatrace Help&lt;/A&gt;) where is&amp;nbsp; no description how to do it (Actually where is no description for this endpoint at all).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Anybody has an idea? Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 10:35:19 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163263#M1173</guid>
      <dc:creator>Ingrida</dc:creator>
      <dc:date>2021-11-18T10:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163297#M1176</link>
      <description>&lt;P&gt;To set management zone permissions call&lt;/P&gt;
&lt;P&gt;PUT&amp;nbsp;/groups/managementZones&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Sample payload:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;{
 "groupId": "test1",
 "mzPermissionsPerEnvironment": [
  {
   "environmentUuid": "e2888c6a-607e-4c18-b817-f317c10a1aa6",
   "mzPermissions": [
    {
     "mzId": "3827223878816945918",
     "permissions": [
      "VIEW_SENSITIVE_REQUEST_DATA",
      "VIEWER",
      "LOG_VIEWER"
     ]
    }
   ]
  },
  {
   "environmentUuid": "0f13a010-f581-4b52-915f-746c96a4c977",
   "mzPermissions": []
  },
  {
   "environmentUuid": "65ca87ab-62eb-41ef-9939-d523a3b20cae",
   "mzPermissions": [
    {
     "mzId": "-263036454330135551",
     "permissions": [
      "VIEWER",
      "REPLAY_SESSION_DATA"
     ]
    }
   ]
  },
  {
   "environmentUuid": "7776be40-7389-42bc-a6dd-e0d4eab206da",
   "mzPermissions": []
  },
  {
   "environmentUuid": "4a74b19f-fd0d-4a92-acc0-bb8e0abb7e1a",
   "mzPermissions": []
  },
  {
   "environmentUuid": "73938789-9f75-4f77-b7d6-54d2dbfbc4a0",
   "mzPermissions": []
  },
  {
   "environmentUuid": "c9a67fe6-8bf8-4bb8-82a1-3ebe8d9ca4d2",
   "mzPermissions": []
  }
 ]
}
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Mar 2021 15:16:44 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163297#M1176</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2021-03-23T15:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163329#M1177</link>
      <description>&lt;P&gt;Thanks for quick reply. Tested and works.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, it mean in case I need to have User Group which has to have access just for certain Management Zones inside some Environments, I have to use two steps approach:&lt;/P&gt;&lt;P&gt;1. Create Group&lt;/P&gt;&lt;P&gt;2. Adjust Groups access regarding Management Zones&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some remakrs / clarification request if possible:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had a group defined as:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; {
    "isClusterAdminGroup": false,
    "id": "test",
    "name": "Test",
    "ldapGroupNames": [
      "test"
    ],
    "accessRight": {
      "VIEWER": [
        "0d267653-6cb1-429f-a5bb-a04afb247e18",
        "9fe2a41e-b402-4a47-b577-9fa64cadd69c"
      ],
      "MANAGE_SETTINGS": [
        "0d267653-6cb1-429f-a5bb-a04afb247e18"
      ]
    }
  }&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I used&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;/groups/managementZones with following content:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;{
 "groupId": "test",
 "mzPermissionsPerEnvironment": [
  {
   "environmentUuid": "19000021-de09-4ea6-8076-81c0163c9c7f",
   "mzPermissions": [
    {
     "mzId": "3477049003423719658",
     "permissions": [
      "VIEW_SENSITIVE_REQUEST_DATA",
      "VIEWER",
      "LOG_VIEWER"
     ]
    }
   ]
  },
  {
   "environmentUuid": "9fe2a41e-b402-4a47-b577-9fa64cadd69c",
   "mzPermissions": []
  },
  {
   "environmentUuid": "0d267653-6cb1-429f-a5bb-a04afb247e18",
   "mzPermissions": [
    {
     "mzId": "1213888254333099543",
     "permissions": [
      "VIEWER",
      "REPLAY_SESSION_DATA" 
      ],
     "mzId": "-3471389981007631349",
     "permissions": [
      "VIEW_SENSITIVE_REQUEST_DATA",
      "VIEWER",
      "LOG_VIEWER"
     ]
    }
   ]
  }
 ]
}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In UI I see excatly what is defined in the JSON above.&lt;/P&gt;&lt;P&gt;However, output of PUT groups/test shows same content as above (with two Environments)&lt;/P&gt;&lt;P&gt;PUT groups/managementZones/test shows content as expected (including empty "permissions" for not defined Environments and Management Zones (does it mean no access or inheritance from definitions above?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 12:54:28 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163329#M1177</guid>
      <dc:creator>Ingrida</dc:creator>
      <dc:date>2021-03-24T12:54:28Z</dc:date>
    </item>
    <item>
      <title>Re: Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163339#M1178</link>
      <description>&lt;P&gt;Hm... there's not resource under `&lt;SPAN&gt;groups/managementZones/test`&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you have a permission set to an environment - you get it to all management zones within an environment.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 13:30:19 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163339#M1178</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2021-03-24T13:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163341#M1179</link>
      <description>&lt;P&gt;Sorry for irritation. I mean I see right set up then I use get&amp;nbsp;&lt;SPAN&gt;groups/managementZones/test. However, with get groups/test I see just set up for 2 Environments. Not 3. I am not sure what it mean. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Another Example: If I check on UI for User Group configuration, I see f.e. that MONITORIG SETTINGS feature is checked for Environment&amp;nbsp;0d267653-6cb1-429f-a5bb-a04afb247e18 but for none of the Management Zones below. Does it mean it is available for all Zones or for none?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 13:50:35 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163341#M1179</guid>
      <dc:creator>Ingrida</dc:creator>
      <dc:date>2021-03-24T13:50:35Z</dc:date>
    </item>
    <item>
      <title>Re: Create User Group with Management Zone level permissions</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163399#M1180</link>
      <description>&lt;P&gt;No worries. Let me rephrase:&lt;/P&gt;
&lt;P&gt;1. &lt;STRONG&gt;GET/groups/managementZones/&amp;lt;groupId&amp;gt;&lt;/STRONG&gt; returns only management zones permissions for a given group. Should be same as in UI in "Management Zones" permission section.&lt;/P&gt;
&lt;P&gt;2.&amp;nbsp;&lt;STRONG&gt;GET&amp;nbsp;&lt;/STRONG&gt;&lt;STRONG&gt;/groups/&amp;lt;groupId&amp;gt;&lt;/STRONG&gt; returns only environment level permissions for a given group. Should be same as in UI in "Environment Permissions" section for a group.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the relation to you example:&lt;/P&gt;
&lt;P&gt;Group "test" allows to access:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Environment: "0d267653-6cb1-429f-a5bb-a04afb247e18" (viewer + manage settings)&lt;/LI&gt;
&lt;LI&gt;Environment: "9fe2a41e-b402-4a47-b577-9fa64cadd69c" (viewer)&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;and additionally to management zones:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;Environment: "19000021-de09-4ea6-8076-81c0163c9c7f"
&lt;UL&gt;
&lt;LI&gt;MZ id "3477049003423719658" (sensitive, viewer, log viewer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Environment: "0d267653-6cb1-429f-a5bb-a04afb247e18"&amp;nbsp;
&lt;UL&gt;
&lt;LI&gt;MZ id "1213888254333099543" (viewer, session replay)&lt;/LI&gt;
&lt;LI&gt;MZ id "-3471389981007631349"&amp;nbsp;(sensitive, viewer, log viewer)&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;Environment: "9fe2a41e-b402-4a47-b577-9fa64cadd69c"
&lt;UL&gt;
&lt;LI&gt;none&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope if you look this way, you see what's expected. For example for the environment "0d267653-6cb1-429f-a5bb-a04afb247e18" group allows to:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- viewer (access) to all management zones (env level perm)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- manage settings to all management zones (env level perm)&lt;/P&gt;
&lt;P&gt;-&amp;nbsp; session replay only for MZ "1213888254333099543"&lt;/P&gt;
&lt;P&gt;- view sensitive data for MZ "-3471389981007631349"&lt;/P&gt;
&lt;P&gt;- log viewer for "-3471389981007631349"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 11:52:32 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Create-User-Group-with-Management-Zone-level-permissions/m-p/163399#M1180</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2021-03-25T11:52:32Z</dc:date>
    </item>
  </channel>
</rss>

