<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Prevent new servers from onboarding in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/229948#M29787</link>
    <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Perhaps&lt;A href="https://docs.dynatrace.com/docs/manage/access-control/access-tokens/rotate-tenant-token#tenant-token" target="_self"&gt; this&lt;/A&gt; can help&lt;/SPAN&gt;&lt;SPAN&gt;. Changing the environment token in a few days &lt;/SPAN&gt;&lt;SPAN&gt;+ prohibiting&lt;/SPAN&gt;&lt;SPAN&gt;/controlling the generation of new PAAS tokens.&amp;nbsp; (This procedure needs to be performed carefully, as if you trigger the start and end within a short interval, you may lose some ActiveGates\OneAgents&amp;nbsp;&amp;nbsp;that haven't had a chance to update their token (for example due inactive/offline state or due network connectivity issues))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In this case already downloaded scripts will contain expired env. token. And after installation from old installation script agens will be rejected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alex Romanenkov&lt;/P&gt;</description>
    <pubDate>Mon, 27 Nov 2023 07:31:32 GMT</pubDate>
    <dc:creator>Romanenkov_Al3x</dc:creator>
    <dc:date>2023-11-27T07:31:32Z</dc:date>
    <item>
      <title>Prevent new servers from onboarding</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/229703#M29741</link>
      <description>&lt;P&gt;Is there any way to prevent users installing the OneAgent to an instance?&amp;nbsp; When migrating from on-prem to SaaS, I'd like to be able to prevent anyone from adding servers to the on-prem environment(s); essentially closing it off.&lt;/P&gt;&lt;P&gt;I know I can remove the Installer Download scope from all of the existing access tokens which would prevent downloads, but what about for installs where the binary is already downloaded?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Nov 2023 19:18:03 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/229703#M29741</guid>
      <dc:creator>John_McLaughlin</dc:creator>
      <dc:date>2023-11-22T19:18:03Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent new servers from onboarding</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/229948#M29787</link>
      <description>&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Perhaps&lt;A href="https://docs.dynatrace.com/docs/manage/access-control/access-tokens/rotate-tenant-token#tenant-token" target="_self"&gt; this&lt;/A&gt; can help&lt;/SPAN&gt;&lt;SPAN&gt;. Changing the environment token in a few days &lt;/SPAN&gt;&lt;SPAN&gt;+ prohibiting&lt;/SPAN&gt;&lt;SPAN&gt;/controlling the generation of new PAAS tokens.&amp;nbsp; (This procedure needs to be performed carefully, as if you trigger the start and end within a short interval, you may lose some ActiveGates\OneAgents&amp;nbsp;&amp;nbsp;that haven't had a chance to update their token (for example due inactive/offline state or due network connectivity issues))&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;In this case already downloaded scripts will contain expired env. token. And after installation from old installation script agens will be rejected.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Alex Romanenkov&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 07:31:32 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/229948#M29787</guid>
      <dc:creator>Romanenkov_Al3x</dc:creator>
      <dc:date>2023-11-27T07:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent new servers from onboarding</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/230011#M29800</link>
      <description>&lt;P&gt;Thanks for the info.&amp;nbsp; Seems kind of daunting to have to perform this on 4000+ hosts however.&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 14:20:10 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/230011#M29800</guid>
      <dc:creator>John_McLaughlin</dc:creator>
      <dc:date>2023-11-27T14:20:10Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent new servers from onboarding</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/230025#M29804</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18456"&gt;@John_McLaughlin&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We have set up a check for the hosts on which the agent must be installed (and which allows us to deactivate those which must not be installed)&lt;/P&gt;&lt;P&gt;First, we implemented an “auto-tagging” rule in order to identify all the hosts that are supposed to be within our monitoring perimeter. (with values like "yes" or "no")&lt;BR /&gt;Depending on the size of the perimeter, this can be a little tedious, but once it's in place, you have peace of mind &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;And then, via a python script that makes API calls, we check all the hosts that do not have this tag, and we deactivate them by API.&lt;BR /&gt;This script can be called according to the frequency you want with a scheduler, or a pipeline, for example.&lt;/P&gt;&lt;P&gt;We even added an event on disabled hosts to track the action, and we send the list of disabled servers in a Teams communication channel to inform the teams.&lt;/P&gt;&lt;P&gt;Subsequently, we created a 3rd possible value, "temporary", for the servers where we were studying the interest of putting an agent there.&lt;/P&gt;&lt;P&gt;I remain available if you are interested in knowing a little more.&lt;BR /&gt;Good luck&lt;/P&gt;</description>
      <pubDate>Mon, 27 Nov 2023 16:06:24 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/230025#M29804</guid>
      <dc:creator>gbaudart</dc:creator>
      <dc:date>2023-11-27T16:06:24Z</dc:date>
    </item>
    <item>
      <title>Re: Prevent new servers from onboarding</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/235671#M30793</link>
      <description>&lt;P&gt;I'm not sure how this would work for my use case.&amp;nbsp; I'd want to disable any future installs by any means, as I migrate to the SaaS platform.&amp;nbsp; I'm not sure how I would set up a tagging rule to *only* tag servers that are currently on my managed environment; and to not have it also apply to any other systems that get added since the would presumably have all of the same requirements as those other machines.&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 15:39:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Prevent-new-servers-from-onboarding/m-p/235671#M30793</guid>
      <dc:creator>John_McLaughlin</dc:creator>
      <dc:date>2024-01-26T15:39:05Z</dc:date>
    </item>
  </channel>
</rss>

