<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't assign iam:groups:read policy to oauth2 client in Dynatrace API</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/269680#M3604</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/78577"&gt;@DaveOps&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You have to send a curl like this:&lt;/P&gt;&lt;P&gt;$ curl --request POST '&lt;A href="https://sso.dynatrace.com/sso/oauth2/token" target="_blank" rel="noopener"&gt;https://sso.dynatrace.com/sso/oauth2/token&lt;/A&gt;' \&lt;BR /&gt;--header 'Content-Type: application/x-www-form-urlencoded' \&lt;BR /&gt;--data-urlencode 'grant_type=client_credentials' \&lt;BR /&gt;--data-urlencode 'client_id=XXXXXXX' \&lt;BR /&gt;--data-urlencode 'client_secret=XXXXXXXXXXXXXXXXXXXXXXXXXX' \&lt;BR /&gt;--data-urlencode 'resource=urn:dtaccount:XXXXXXX' \&lt;BR /&gt;--data-urlencode 'scope=iam:users:read iam:groups:read'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But first, you have to create an &lt;A href="https://docs.dynatrace.com/managed/shortlink/oauth#create-an-oauth2-client" target="_self"&gt;OAuth client&lt;/A&gt; selecting the scopes you need.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Elena.&lt;/P&gt;</description>
    <pubDate>Tue, 11 Feb 2025 06:13:20 GMT</pubDate>
    <dc:creator>erh_inetum</dc:creator>
    <dc:date>2025-02-11T06:13:20Z</dc:date>
    <item>
      <title>Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255568#M3379</link>
      <description>&lt;P&gt;Can't assign `iam:groups:read` policy to oauth2 client to be able to get a bearer token via sso which allows me to interact with the `/platform/iam/v1` api.&lt;/P&gt;
&lt;P&gt;Received the following response:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="javascript"&gt;{

    "error": {

        "code": 403,

        "message": "User not authorized."

    }

}&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;Please advise.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2024 06:21:39 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255568#M3379</guid>
      <dc:creator>DaveOps</dc:creator>
      <dc:date>2024-09-13T06:21:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255587#M3380</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Could you please provide the request that you executed?&lt;/P&gt;&lt;P&gt;Best Regards&lt;BR /&gt;Patryk&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 13:01:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255587#M3380</guid>
      <dc:creator>patryk_ozimek2</dc:creator>
      <dc:date>2024-09-12T13:01:06Z</dc:date>
    </item>
    <item>
      <title>Re: Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255595#M3382</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;GET https://{environmentid}.apps.dynatrace.com/platform/iam/v1/organizational-levels/environment/tkx85859/groups?partialGroupName=poc&amp;amp;pageSize=1000403
290 ms
GET /platform/iam/v1/organizational-levels/environment/tkx85859/groups?partialGroupName=poc&amp;amp;pageSize=1000 HTTP/1.1
Authorization: Bearer eyJhbGciOiJFUzI1NiIsInR5cCI6IkpXVCIsImtpZCI6IjEifQ.eyJzdWIiOiIyOTQxMDc1Yi1lYjM0LTQwZmYtYTE3MC01M2M1NjIyYWVjNDciLCJyZXMiOiJ1cm46ZHRhY2NvdW50OmNmYmU0ZGRmLWZkOTktNDU4ZS1iMmE2LWJkNDQ5OTRlZmQxMSIsIl9jbGFpbV9uYW1lcyI6eyJncm91cHMiOiIwIn0sInByZWZlcnJlZF91c2VybmFtZSI6IjI5NDEwNzViLWViMzQtNDBmZi1hMTcwLTUzYzU2MjJhZWM0N0BzZXJ2aWNlLnNzby5keW5hdHJhY2UuY29tIiwiZ3QiOiJjYyIsImludCI6ZmFsc2UsImF1ZCI6ImR0MHMwMi5ZTllLRlI1SCIsInNjb3BlIjoiYWNjb3VudC1lbnYtcmVhZCBhY2NvdW50LWlkbS1yZWFkIiwiX2NsYWltX3NvdXJjZXMiOnsiMCI6eyJlbmRwb2ludCI6bnVsbH19LCJleHAiOjE3MjYxNDg5NjQsImlhdCI6MTcyNjE0ODY2NCwianRpIjoiNjZkMWMzMmItZTBkYS00ZDg1LWE4MWItNmZiMTFhNDY3NzNlIiwiZW1haWwiOiIyOTQxMDc1Yi1lYjM0LTQwZmYtYTE3MC01M2M1NjIyYWVjNDdAc2VydmljZS5zc28uZHluYXRyYWNlLmNvbSJ9._obETzSjgLjpCivGhSeA4GO2Rb1UH9tXlovKyqUB7GCpwmTieVILER1TpqykMwh_Dr44XcP1exDXGEiPb7_PKw
User-Agent: PostmanRuntime/7.41.2
Accept: */*
Cache-Control: no-cache
Postman-Token: 4c14a859-de4a-4bb2-9db2-515a08350d6b
Host: tkx85859.apps.dynatrace.com
Accept-Encoding: gzip, deflate, br
Connection: keep-alive
Cookie: AWSALB=HsIT5W022Crk334QBTqgjGr1P1C1OWh8AHF1cJMEYjlhljzpzLS2MVsH+JrjPGRVtithHfwKELtbFLjDWGW+pKBlEu659oqIGMrqm6vSMOzBu9p5HswhqF1PCjDe; AWSALBCORS=HsIT5W022Crk334QBTqgjGr1P1C1OWh8AHF1cJMEYjlhljzpzLS2MVsH+JrjPGRVtithHfwKELtbFLjDWGW+pKBlEu659oqIGMrqm6vSMOzBu9p5HswhqF1PCjDe
 
HTTP/1.1 403 Forbidden
vary: Origin,Access-Control-Request-Method,Access-Control-Request-Headers,Accept-Encoding
date: Thu, 12 Sep 2024 13:44:50 GMT
content-type: application/json
content-length: 55
set-cookie: AWSALB=LZuDggOsubvZC5njtw6JCIpkchUnewTFivwz1lPERu4pNHdTT/TVuGqDPjizUY8LI0vMxBrvh6JDt1y3/zm3O8zP6lKmO8bJhOf9jdoSmDaXddsqgC2y7pLWnfdN; Expires=Thu, 19 Sep 2024 13:44:50 GMT; Path=/
set-cookie: AWSALBCORS=LZuDggOsubvZC5njtw6JCIpkchUnewTFivwz1lPERu4pNHdTT/TVuGqDPjizUY8LI0vMxBrvh6JDt1y3/zm3O8zP6lKmO8bJhOf9jdoSmDaXddsqgC2y7pLWnfdN; Expires=Thu, 19 Sep 2024 13:44:50 GMT; Path=/; SameSite=None; Secure
strict-transport-security: max-age=31536000
cache-control: no-cache, no-store, must-revalidate
pragma: no-cache
expires: 0
dynatrace-response-source: Service
x-content-type-options: nosniff
x-xss-protection: 0
referrer-policy: strict-origin-when-cross-origin
traceresponse: 00-0f2113aef68326bccb3bc02310b4e92b-443eccf561ea5e80-01
x-dt-tracestate: 67e0a59d-8e83bf33@dt
 
{"error":{"code":403,"message":"User not authorized."}}&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Sep 2024 13:46:33 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/255595#M3382</guid>
      <dc:creator>DaveOps</dc:creator>
      <dc:date>2024-09-12T13:46:33Z</dc:date>
    </item>
    <item>
      <title>Re: Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/257138#M3398</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/78577"&gt;@DaveOps&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can validate the current configuration with IAM team against the provided documentation URL for step-by-step instructions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/managed/manage/identity-access-management/access-tokens-and-oauth-clients/oauth-clients" target="_self"&gt;access-tokens-and-oauth-clients&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;A href="https://docs.dynatrace.com/managed/manage/identity-access-management/access-tokens-and-oauth-clients/access-tokens" target="_self"&gt;access-tokens&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Peter.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Sep 2024 19:18:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/257138#M3398</guid>
      <dc:creator>Peter_Youssef</dc:creator>
      <dc:date>2024-09-25T19:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/266536#M3543</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/78577"&gt;@DaveOps&lt;/a&gt;! Have you managed to find the answer to your question? It would be great if you share it with the Community &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Jan 2025 15:40:11 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/266536#M3543</guid>
      <dc:creator>GosiaMurawska</dc:creator>
      <dc:date>2025-01-02T15:40:11Z</dc:date>
    </item>
    <item>
      <title>Re: Can't assign iam:groups:read policy to oauth2 client</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/269680#M3604</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/78577"&gt;@DaveOps&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You have to send a curl like this:&lt;/P&gt;&lt;P&gt;$ curl --request POST '&lt;A href="https://sso.dynatrace.com/sso/oauth2/token" target="_blank" rel="noopener"&gt;https://sso.dynatrace.com/sso/oauth2/token&lt;/A&gt;' \&lt;BR /&gt;--header 'Content-Type: application/x-www-form-urlencoded' \&lt;BR /&gt;--data-urlencode 'grant_type=client_credentials' \&lt;BR /&gt;--data-urlencode 'client_id=XXXXXXX' \&lt;BR /&gt;--data-urlencode 'client_secret=XXXXXXXXXXXXXXXXXXXXXXXXXX' \&lt;BR /&gt;--data-urlencode 'resource=urn:dtaccount:XXXXXXX' \&lt;BR /&gt;--data-urlencode 'scope=iam:users:read iam:groups:read'&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But first, you have to create an &lt;A href="https://docs.dynatrace.com/managed/shortlink/oauth#create-an-oauth2-client" target="_self"&gt;OAuth client&lt;/A&gt; selecting the scopes you need.&lt;/P&gt;&lt;P&gt;Hope it helps.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Elena.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Feb 2025 06:13:20 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Can-t-assign-iam-groups-read-policy-to-oauth2-client/m-p/269680#M3604</guid>
      <dc:creator>erh_inetum</dc:creator>
      <dc:date>2025-02-11T06:13:20Z</dc:date>
    </item>
  </channel>
</rss>

