<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Policies for Access Tokens? in Dynatrace API</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222916#M2875</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't remember there being an option to narrow down the permissions that much. What I would try is to create permissions (Manage monitoring settings)for a specific Management Zone. Then you would gain permissions to configure alert profiles, for example.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Manage monitoring settings: Allows the changing of entity settings within a management zone, for example, the ability to record or edit synthetic monitors. It also grants access to some items in the global settings menu but only allows making modifications to assigned management zones. For example, alerting profiles can only be created and changed for a specific management zone."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For the API, you have to use the settings.read and settings.write scopes to make the changes you want:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/dynatrace-api/environment-api/settings/schemas/builtin-alerting-profile" target="_blank"&gt;https://www.dynatrace.com/support/help/dynatrace-api/environment-api/settings/schemas/builtin-alerting-profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can narrow down the scope by specifying additional parameters like the name of the MZ, etc....&lt;/P&gt;&lt;P&gt;Radek&lt;/P&gt;</description>
    <pubDate>Wed, 13 Sep 2023 10:05:33 GMT</pubDate>
    <dc:creator>radek_jasinski</dc:creator>
    <dc:date>2023-09-13T10:05:33Z</dc:date>
    <item>
      <title>Policies for Access Tokens</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222905#M2874</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;For a customer it would be ideal if I could get an access token with custom policies instead of the pre-set write settings.&lt;/P&gt;
&lt;P&gt;I need a token with two very specific policies assigned to it. Edit alerting profiles and edit notifications. Is it possible to connect tokens and policies or select a custom scope of tokens? As far as I know, policies are specific to user accounts but maybe someone has an idea or I am missing something. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; Help is greatly appreciated!&lt;/P&gt;</description>
      <pubDate>Mon, 16 Oct 2023 17:22:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222905#M2874</guid>
      <dc:creator>marina_pollehn</dc:creator>
      <dc:date>2023-10-16T17:22:08Z</dc:date>
    </item>
    <item>
      <title>Re: Policies for Access Tokens?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222916#M2875</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I don't remember there being an option to narrow down the permissions that much. What I would try is to create permissions (Manage monitoring settings)for a specific Management Zone. Then you would gain permissions to configure alert profiles, for example.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;"Manage monitoring settings: Allows the changing of entity settings within a management zone, for example, the ability to record or edit synthetic monitors. It also grants access to some items in the global settings menu but only allows making modifications to assigned management zones. For example, alerting profiles can only be created and changed for a specific management zone."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;For the API, you have to use the settings.read and settings.write scopes to make the changes you want:&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/dynatrace-api/environment-api/settings/schemas/builtin-alerting-profile" target="_blank"&gt;https://www.dynatrace.com/support/help/dynatrace-api/environment-api/settings/schemas/builtin-alerting-profile&lt;/A&gt;&lt;/P&gt;&lt;P&gt;You can narrow down the scope by specifying additional parameters like the name of the MZ, etc....&lt;/P&gt;&lt;P&gt;Radek&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 10:05:33 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222916#M2875</guid>
      <dc:creator>radek_jasinski</dc:creator>
      <dc:date>2023-09-13T10:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Policies for Access Tokens?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222926#M2876</link>
      <description>&lt;P&gt;The problem is that these permissions are only usable for users, not tokens/API . &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt; the read and write API settings are way to broad for us.... Maybe something can be achieved with some scripting here.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 11:34:02 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222926#M2876</guid>
      <dc:creator>marina_pollehn</dc:creator>
      <dc:date>2023-09-13T11:34:02Z</dc:date>
    </item>
    <item>
      <title>Re: Policies for Access Tokens?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222936#M2877</link>
      <description>&lt;P&gt;In my opinion, this is currently the only method. You can submit a product idea for Dynatrace to allow more complex permission management on the settings tab.&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 13 Sep 2023 12:11:59 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Policies-for-Access-Tokens/m-p/222936#M2877</guid>
      <dc:creator>radek_jasinski</dc:creator>
      <dc:date>2023-09-13T12:11:59Z</dc:date>
    </item>
  </channel>
</rss>

