<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to properly provide access to New UI based on Management Zones permissions in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/236650#M30959</link>
    <description>&lt;P&gt;Yep, just tested and worked as expected.&lt;/P&gt;&lt;P&gt;I have still used the Management Zones to limit the entity access in general UI views (host classic page, dashboard classic, data explorer, etc.) And for Grail access with DQL, I had to use the polices limiting the access by hostgroup (but I do assume it can be any metadata)&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ALLOW storage:buckets:read;
ALLOW storage:entities:read;
ALLOW storage:system:read;
ALLOW storage:metrics:read
WHERE storage:dt.host_group.id STARTSWITH "my_host_group";&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not easy, but doable.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Feb 2024 18:18:19 GMT</pubDate>
    <dc:creator>dannemca</dc:creator>
    <dc:date>2024-02-08T18:18:19Z</dc:date>
    <item>
      <title>Properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217592#M27476</link>
      <description>&lt;P&gt;The new UI is there and we can use polices to provide users access to, based on this &lt;A href="https://www.dynatrace.com/news/blog/tailored-access-management-part-2-onboard-users-to-grail-and-appengine/" target="_self"&gt;blog post&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;But, my current env access is totally based on Management Zones. We have many teams which can access specific Management Zones, with no special permissions, other than access env and change monitoring permissions. We are not using polices yet, since not required. Until now.&lt;/P&gt;
&lt;P&gt;The appengine and grail access is not scoped at Management Zone levels, but entire environment, so I am struggling to proper set the polices rules for it.&lt;/P&gt;
&lt;P&gt;Has anyone face the same challenge?&lt;/P&gt;
&lt;P&gt;Any tip for the friend here?&lt;/P&gt;
&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 08:40:43 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217592#M27476</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2024-03-07T08:40:43Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217594#M27477</link>
      <description>&lt;P&gt;Facing exactly same challenge as you &lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt; currently under investigation by my side.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 17:38:39 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217594#M27477</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2023-07-11T17:38:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217601#M27478</link>
      <description>&lt;P&gt;I also let you know that I have a case with a detected bug if you have a policy with more than 100 lines you cannot edit it, they will notify me of a possible ETA for the solution. I found this when I was doing tests related to this topic.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 18:16:40 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217601#M27478</guid>
      <dc:creator>DanielS</dc:creator>
      <dc:date>2023-07-11T18:16:40Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217626#M27481</link>
      <description>&lt;P&gt;Well, I heard on a call last week that Management Zones are going away in roughly 18-24 months.&amp;nbsp; I am trying to get more info on this from my account team and from the Western group that I was in and it was brought up on a call with IAM Policies.&amp;nbsp; Will let you know when I hear more and find out more details.&amp;nbsp; Very early stages from what I hear.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jul 2023 19:40:30 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/217626#M27481</guid>
      <dc:creator>Kenny_Gillette</dc:creator>
      <dc:date>2023-07-11T19:40:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/230356#M29863</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/36140"&gt;@Kenny_Gillette&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;have you managed to get more information on the possible removal of management zones? this is also a key point for us, and we've heard absolutely nothing about it.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 07:55:27 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/230356#M29863</guid>
      <dc:creator>GerardJ</dc:creator>
      <dc:date>2023-11-30T07:55:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/230453#M29877</link>
      <description>&lt;P&gt;no information yet.&amp;nbsp; Just reached out to my contacts at Dynatrace and they are researching.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:04:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/230453#M29877</guid>
      <dc:creator>Kenny_Gillette</dc:creator>
      <dc:date>2023-11-30T15:04:37Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/235563#M30773</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/18264"&gt;@dannemca&lt;/a&gt;&amp;nbsp;, Have you by any chance found an answer to your question , I am running into the same issue here..&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2024 18:56:08 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/235563#M30773</guid>
      <dc:creator>soukainaB</dc:creator>
      <dc:date>2024-01-25T18:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/235588#M30774</link>
      <description>&lt;P&gt;Did you test the script mentioned in this blog entry?&lt;BR /&gt;&lt;A href="https://www.dynatrace.com/news/blog/tailored-access-management-part-2-onboard-users-to-grail-and-appengine/" target="_blank"&gt;https://www.dynatrace.com/news/blog/tailored-access-management-part-2-onboard-users-to-grail-and-appengine/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 26 Jan 2024 07:15:52 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/235588#M30774</guid>
      <dc:creator>PacoPorro</dc:creator>
      <dc:date>2024-01-26T07:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/236647#M30957</link>
      <description>&lt;P&gt;I believe the access issue can be managed using custom buckets and polices, as per this blog: &lt;A href="https://www.dynatrace.com/news/blog/enhance-data-management-with-grail-ultimate-guide-to-custom-buckets-and-security-policies/" target="_blank"&gt;https://www.dynatrace.com/news/blog/enhance-data-management-with-grail-ultimate-guide-to-custom-buckets-and-security-policies/&lt;/A&gt; and this video: &lt;A href="https://info.dynatrace.com/global-rm-enhanced-access-controls-with-record-level-permissions-23267-fulfillment.html" target="_blank"&gt;https://info.dynatrace.com/global-rm-enhanced-access-controls-with-record-level-permissions-23267-fulfillment.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;It does mention logs, but I believe it can be also applied to metrics buckets too.&lt;/P&gt;&lt;P&gt;I will do some tests and see if that works.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 17:37:10 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/236647#M30957</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2024-02-08T17:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to properly provide access to New UI based on Management Zones permissions</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/236650#M30959</link>
      <description>&lt;P&gt;Yep, just tested and worked as expected.&lt;/P&gt;&lt;P&gt;I have still used the Management Zones to limit the entity access in general UI views (host classic page, dashboard classic, data explorer, etc.) And for Grail access with DQL, I had to use the polices limiting the access by hostgroup (but I do assume it can be any metadata)&lt;/P&gt;&lt;P&gt;Example:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;ALLOW storage:buckets:read;
ALLOW storage:entities:read;
ALLOW storage:system:read;
ALLOW storage:metrics:read
WHERE storage:dt.host_group.id STARTSWITH "my_host_group";&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is not easy, but doable.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Feb 2024 18:18:19 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Properly-provide-access-to-New-UI-based-on-Management-Zones/m-p/236650#M30959</guid>
      <dc:creator>dannemca</dc:creator>
      <dc:date>2024-02-08T18:18:19Z</dc:date>
    </item>
  </channel>
</rss>

