<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is It Possible to Create a Policy That Allows the account-idm-read Scope for a Service User? in Dynatrace API</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288830#M3872</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/74836"&gt;@ASE&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Apologies for the delayed response.&lt;BR /&gt;I needed some time to fully understand the new functionality and its implications.&lt;/P&gt;&lt;P&gt;And thank you very much for posting the &lt;A href="https://community.dynatrace.com/t5/Product-ideas/Support-user-and-group-read-scopes-in-Platform-Tokens/idi-p/288284" target="_blank"&gt;product idea&lt;/A&gt;,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;.&lt;BR /&gt;I now understand that our goal is more appropriately achieved using Platform Tokens rather than an OAuth Client — I'm glad to have that clarified.&lt;/P&gt;&lt;P&gt;I’ll share this product idea with my colleagues and the customer.&lt;BR /&gt;It would be greatly appreciated if this feature could be considered for implementation!&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Natsumi Tanaka&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Oct 2025 05:36:36 GMT</pubDate>
    <dc:creator>ntanaka</dc:creator>
    <dc:date>2025-10-30T05:36:36Z</dc:date>
    <item>
      <title>Is It Possible to Create a Policy That Allows the account-idm-read Scope for a Service User?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/287175#M3854</link>
      <description>&lt;P&gt;&lt;STRONG&gt;Goal:&lt;/STRONG&gt;&lt;BR /&gt;Our customer would like to create a service user that can utilize the User Management API to list all users:&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/account-api-users-get-all" target="_self"&gt;https://docs.dynatrace.com/docs/shortlink/account-api-users-get-all&lt;/A&gt;&lt;BR /&gt;The reason for creating a service user is to avoid the need to recreate the associated OAuth client when an authorized user leaves the organization and their Dynatrace account is deleted.&lt;BR /&gt;To prevent this, they would prefer to use a service user that is not tied to a specific individual.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Problem:&lt;/STRONG&gt;&lt;BR /&gt;The required scope for the API, account-idm-read, is not listed as a policy statement.&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/iam-policystatements" target="_self"&gt;https://docs.dynatrace.com/docs/shortlink/iam-policystatements&lt;/A&gt;&lt;BR /&gt;However, when attempting to create a service user, it is necessary to define a policy.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Question:&lt;/STRONG&gt;&lt;BR /&gt;Could you please confirm whether it is possible to create a policy that allows the account-idm-read scope?&lt;BR /&gt;If not, are there any plans to support this in future updates?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Oct 2025 05:49:16 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/287175#M3854</guid>
      <dc:creator>ntanaka</dc:creator>
      <dc:date>2025-10-03T05:49:16Z</dc:date>
    </item>
    <item>
      <title>Re: Is It Possible to Create a Policy That Allows the account-idm-read Scope for a Service User?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288274#M3863</link>
      <description>&lt;P&gt;Thank you for this,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/13672"&gt;@ntanaka&lt;/a&gt;.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We are also in need of this very same thing.&lt;BR /&gt;&lt;BR /&gt;I want to grant the new Service Account the ability to view all Dynatrace Users, without doing it via the &lt;STRONG&gt;Account Management&lt;/STRONG&gt; page.&lt;/P&gt;&lt;P&gt;Looks like the &lt;STRONG&gt;Account Management&lt;/STRONG&gt; permissions are a completely separate thing, and I'm not finding a breakdown of exactly what they are.&lt;BR /&gt;&lt;BR /&gt;I only want to allow &lt;STRONG&gt;View&lt;/STRONG&gt; and that's it.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ASE_0-1761079526544.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/30636i522D72E7E789A86D/image-size/medium?v=v2&amp;amp;px=400" role="button" title="ASE_0-1761079526544.png" alt="ASE_0-1761079526544.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Oct 2025 20:47:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288274#M3863</guid>
      <dc:creator>ASE</dc:creator>
      <dc:date>2025-10-21T20:47:03Z</dc:date>
    </item>
    <item>
      <title>Re: Is It Possible to Create a Policy That Allows the account-idm-read Scope for a Service User?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288285#M3864</link>
      <description>&lt;P&gt;You could do it for service users, but not yet for mere users. But is a little bit different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For reference &lt;A href="https://docs.dynatrace.com/docs/shortlink/platform-tokens" target="_self"&gt;Platform Tokens&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;The user executing this needs to have a policy for handling service users:&lt;/LI&gt;&lt;/UL&gt;&lt;LI-CODE lang="markup"&gt;ALLOW iam:service-users:use; 
OR IF YOU WANT TO BE MORE SPECIFIC
ALLOW iam:service-users:use WHERE iam:service-user-email = "service-user-email@email.com";​&lt;/LI-CODE&gt;&lt;OL&gt;&lt;LI&gt;Go to&amp;nbsp;&lt;A href="https://myaccount.dynatrace.com/platformTokens" target="_blank" rel="noopener"&gt;My platform tokens | Account Management&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Create a new Platform Token&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielS_1-1761093887885.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/30641i133E8F79A6F12DF7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielS_1-1761093887885.png" alt="DanielS_1-1761093887885.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;And select the service user you want to give the required scopes.&lt;/LI&gt;&lt;LI&gt;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt;&lt;SPAN&gt;Platform tokens with service users are not supported for multiple environments&lt;/SPAN&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":warning:"&gt;⚠️&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;Then you can assign&amp;nbsp;&lt;SPAN&gt;iam:service-users:use&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;Call&amp;nbsp;curl -X 'GET' \ 'https://{YOUR TENANT ID}.apps.dynatrace.com/platform/iam/v1/organizational-levels/environment/{YOUR TENANT ID}/service-users' \ -H 'accept: application/json' \ -H 'Authorization: Bearer {YOUR PLATFORM TOKEN}&lt;/LI&gt;&lt;LI&gt;Here you can see that the Platform Token for service account is used&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DanielS_0-1761098928772.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/30642i543808C1E8B64085/image-size/medium?v=v2&amp;amp;px=400" role="button" title="DanielS_0-1761098928772.png" alt="DanielS_0-1761098928772.png" /&gt;&lt;/span&gt;&lt;/LI&gt;&lt;LI&gt;For users you need to invoke&amp;nbsp;curl -X 'GET' \ 'https://{YOUR TENANT ID}.apps.dynatrace.com/platform/iam/v1/organizational-levels/environment/{YOUR TENANT ID}/users?pageSize=1000' \ -H 'accept: application/json' \ -H 'Authorization: Bearer&amp;nbsp;{YOUR PLATFORM TOKEN} but the only problem here is you cannot assign scope&amp;nbsp;&lt;SPAN&gt;iam:users:read&lt;/SPAN&gt;&amp;nbsp;in Platform tokens.&lt;/LI&gt;&lt;LI&gt;I leave you this &lt;A href="https://community.dynatrace.com/t5/Product-ideas/Idea-Support-User-amp-Group-Read-Scopes-in-Platform-Tokens/idi-p/288284" target="_blank" rel="noopener"&gt;product idea&lt;/A&gt; to be able to add this scope to Platform Tokens.&lt;/LI&gt;&lt;/OL&gt;</description>
      <pubDate>Wed, 22 Oct 2025 02:36:42 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288285#M3864</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2025-10-22T02:36:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is It Possible to Create a Policy That Allows the account-idm-read Scope for a Service User?</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288830#M3872</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/74836"&gt;@ASE&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Apologies for the delayed response.&lt;BR /&gt;I needed some time to fully understand the new functionality and its implications.&lt;/P&gt;&lt;P&gt;And thank you very much for posting the &lt;A href="https://community.dynatrace.com/t5/Product-ideas/Support-user-and-group-read-scopes-in-Platform-Tokens/idi-p/288284" target="_blank"&gt;product idea&lt;/A&gt;,&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/35788"&gt;@DanielS&lt;/a&gt;.&lt;BR /&gt;I now understand that our goal is more appropriately achieved using Platform Tokens rather than an OAuth Client — I'm glad to have that clarified.&lt;/P&gt;&lt;P&gt;I’ll share this product idea with my colleagues and the customer.&lt;BR /&gt;It would be greatly appreciated if this feature could be considered for implementation!&lt;/P&gt;&lt;P&gt;Best Regards,&lt;BR /&gt;Natsumi Tanaka&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Oct 2025 05:36:36 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-API/Is-It-Possible-to-Create-a-Policy-That-Allows-the-account-idm/m-p/288830#M3872</guid>
      <dc:creator>ntanaka</dc:creator>
      <dc:date>2025-10-30T05:36:36Z</dc:date>
    </item>
  </channel>
</rss>

