<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change Access Token Owner in Dynatrace API</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212246#M2495</link>
    <description>&lt;P&gt;Thank you everyone for your feedback.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/14877"&gt;@ChadTurner&lt;/a&gt;&amp;nbsp; - I thought so as well but looks like you can for Credential Vault but not for Access Tokens. It is a good tip to know that if you submit a change to a Credential Vault using an Access Token owned by someone else it changes the owner to the person that last edited.&amp;nbsp; &amp;nbsp;This actually causes a problem with our Secret Server process that changes passwords with a robot so no human knows the code, but it causes the robot to take ownership.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;&amp;nbsp; - it would be a good RFE, but DT will shoot it down for security reasons. I've already had some battles in the Access Token zone with them and have lost every one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3364"&gt;@Julius_Loman&lt;/a&gt;&amp;nbsp; - Correct, that's the same findings we've all had I was just hoping i was missing something.&amp;nbsp; Actually the reason we want to do this is for the same security reason you say.&amp;nbsp; A resource developed a few things and since we're not at a corporation security can be a bit more lax here, not discarded, just more lax.&amp;nbsp; We want to move this Access Token to a technical account for security but we can't risk right now breaking the unknowns. So, we wanted to change the owner to fix the situation.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh well, thank you everyone for your input. DynaMights rock!!!&lt;/P&gt;&lt;P&gt;The solution: We're going to generate a new token under a technical account and replace what we know, I think we know of all the critical ones. Then deactivate the old account to see what breaks.&amp;nbsp; Hmmm....would be cool if DT maybe provided some audit details on what's been accessing the token over the past 30+ days (cough, cough...that RFE is around here somewhere).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[UPDATE CT_27 6/2/2023]&amp;nbsp; The RFE referenced above was created in Nov. 2022 please Kudo it. Here is the&amp;nbsp;&amp;nbsp;&lt;A title="RFE Link" href="https://community.dynatrace.com/t5/Product-ideas/Dynatrace-SaaS-Getting-Access-Token-Usage-Information/idi-p/198700#M33891" target="_blank" rel="noopener"&gt;RFE Link&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 02 Jun 2023 13:36:13 GMT</pubDate>
    <dc:creator>ct_27</dc:creator>
    <dc:date>2023-06-02T13:36:13Z</dc:date>
    <item>
      <title>Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211947#M2482</link>
      <description>&lt;P&gt;Scenario:&amp;nbsp; &amp;nbsp;An employee creates multiple solution for a department using Dynatrace APIs.&amp;nbsp; This employee used their own ID to create a API Token to be used in all of his solutions. This employee leaves the organization but we need the API Token to continue working and change it's owner.&lt;/P&gt;
&lt;P&gt;Is there a way in Dynatrace to change the 'Owner' of an existing API Token?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2023 08:53:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211947#M2482</guid>
      <dc:creator>ct_27</dc:creator>
      <dc:date>2023-05-12T08:53:08Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211950#M2483</link>
      <description>&lt;P&gt;I think that can be done via the API in Environment V2.&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 15:44:15 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211950#M2483</guid>
      <dc:creator>ChadTurner</dc:creator>
      <dc:date>2023-05-11T15:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211972#M2484</link>
      <description>&lt;P&gt;Unfortunately the PUT Token API is not able to change the Token owner..&lt;BR /&gt;&lt;A href="https://www.dynatrace.com/support/help/dynatrace-api/environment-api/tokens-v2/api-tokens/put-token" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/dynatrace-api/environment-api/tokens-v2/api-tokens/put-token&lt;/A&gt;&lt;BR /&gt;You can rename, enable/disable, add/remove scopes only.&lt;/P&gt;&lt;P&gt;Let's open an idea for that.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 May 2023 19:08:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/211972#M2484</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2023-05-11T19:08:47Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212166#M2494</link>
      <description>&lt;P&gt;The only proper solution is to rotate the tokens (manually or automatically) or use tokens created by a technical account which won't leave the company.&amp;nbsp;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I don't think changing the ownership is from a security point of view.&lt;/P&gt;</description>
      <pubDate>Sun, 14 May 2023 18:36:43 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212166#M2494</guid>
      <dc:creator>Julius_Loman</dc:creator>
      <dc:date>2023-05-14T18:36:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212246#M2495</link>
      <description>&lt;P&gt;Thank you everyone for your feedback.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/14877"&gt;@ChadTurner&lt;/a&gt;&amp;nbsp; - I thought so as well but looks like you can for Credential Vault but not for Access Tokens. It is a good tip to know that if you submit a change to a Credential Vault using an Access Token owned by someone else it changes the owner to the person that last edited.&amp;nbsp; &amp;nbsp;This actually causes a problem with our Secret Server process that changes passwords with a robot so no human knows the code, but it causes the robot to take ownership.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;&amp;nbsp; - it would be a good RFE, but DT will shoot it down for security reasons. I've already had some battles in the Access Token zone with them and have lost every one.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/3364"&gt;@Julius_Loman&lt;/a&gt;&amp;nbsp; - Correct, that's the same findings we've all had I was just hoping i was missing something.&amp;nbsp; Actually the reason we want to do this is for the same security reason you say.&amp;nbsp; A resource developed a few things and since we're not at a corporation security can be a bit more lax here, not discarded, just more lax.&amp;nbsp; We want to move this Access Token to a technical account for security but we can't risk right now breaking the unknowns. So, we wanted to change the owner to fix the situation.&amp;nbsp; &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Oh well, thank you everyone for your input. DynaMights rock!!!&lt;/P&gt;&lt;P&gt;The solution: We're going to generate a new token under a technical account and replace what we know, I think we know of all the critical ones. Then deactivate the old account to see what breaks.&amp;nbsp; Hmmm....would be cool if DT maybe provided some audit details on what's been accessing the token over the past 30+ days (cough, cough...that RFE is around here somewhere).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[UPDATE CT_27 6/2/2023]&amp;nbsp; The RFE referenced above was created in Nov. 2022 please Kudo it. Here is the&amp;nbsp;&amp;nbsp;&lt;A title="RFE Link" href="https://community.dynatrace.com/t5/Product-ideas/Dynatrace-SaaS-Getting-Access-Token-Usage-Information/idi-p/198700#M33891" target="_blank" rel="noopener"&gt;RFE Link&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:36:13 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212246#M2495</guid>
      <dc:creator>ct_27</dc:creator>
      <dc:date>2023-06-02T13:36:13Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212247#M2496</link>
      <description>&lt;P&gt;Just a quick note - if it is Dynatrace Managed - you can create such tokens with the built-in admin user. That user will never leave the company&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_sunglasses:"&gt;😎&lt;/span&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 15 May 2023 14:10:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/212247#M2496</guid>
      <dc:creator>Julius_Loman</dc:creator>
      <dc:date>2023-05-15T14:10:27Z</dc:date>
    </item>
    <item>
      <title>Re: Change Access Token Owner</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/213952#M2532</link>
      <description>&lt;P&gt;ok, so my situation is worse than expected and it's self inflicted.&amp;nbsp; &amp;nbsp;So, back before Dynatrace had Private Tokens I was the sole admin and created many API Tokens for people to do things and develop applications.&amp;nbsp; We were like 3 days into Dynatrace so we were still learning.&lt;/P&gt;&lt;P&gt;If one day i decide to leave my company I now have a huge issue on my hands. All these important Keys have me as the owner. [NOTE: I'm on SaaS, which unlike Managed doesn't have a special Admin Account]&lt;/P&gt;&lt;P&gt;Dynatrace......is there any way to take these old Tokens and change the ownership?&amp;nbsp; (I'll open a support case now) I'm sharing this in the forum in case others are in a similar situation or can learn from my actions.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Jun 2023 13:41:07 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Change-Access-Token-Owner/m-p/213952#M2532</guid>
      <dc:creator>ct_27</dc:creator>
      <dc:date>2023-06-02T13:41:07Z</dc:date>
    </item>
  </channel>
</rss>

