<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IAM policy not taking effect in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248482#M32791</link>
    <description>&lt;P&gt;Hi folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking to lock down the ability to view logs from a certain host group with the following IAM policy:&lt;BR /&gt;&lt;EM&gt;"ALLOW storage:logs:read WHERE storage:dt.host_group.id = "Hostgroup2";"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In theory this should lock down my user to only be able to view logs for logs written by hosts in "Hostgroup2" HOWEVER when applying the policy my user is still able to see logs written by all host groups.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Is anyone able to advise? i have followed the syntax and conditions defined in the IAM service reference documentation.&lt;/P&gt;</description>
    <pubDate>Tue, 18 Jun 2024 06:58:47 GMT</pubDate>
    <dc:creator>JamesD09</dc:creator>
    <dc:date>2024-06-18T06:58:47Z</dc:date>
    <item>
      <title>IAM policy not taking effect</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248482#M32791</link>
      <description>&lt;P&gt;Hi folks,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am looking to lock down the ability to view logs from a certain host group with the following IAM policy:&lt;BR /&gt;&lt;EM&gt;"ALLOW storage:logs:read WHERE storage:dt.host_group.id = "Hostgroup2";"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;In theory this should lock down my user to only be able to view logs for logs written by hosts in "Hostgroup2" HOWEVER when applying the policy my user is still able to see logs written by all host groups.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Is anyone able to advise? i have followed the syntax and conditions defined in the IAM service reference documentation.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 06:58:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248482#M32791</guid>
      <dc:creator>JamesD09</dc:creator>
      <dc:date>2024-06-18T06:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: IAM policy not taking effect</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248484#M32792</link>
      <description>&lt;P&gt;You can see from the Policy review below the condition is set but does not take effect:&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="JamesD09_0-1718648577622.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/20586iEA75C325620D77A1/image-size/medium?v=v2&amp;amp;px=400" role="button" title="JamesD09_0-1718648577622.png" alt="JamesD09_0-1718648577622.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 Jun 2024 18:23:04 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248484#M32792</guid>
      <dc:creator>JamesD09</dc:creator>
      <dc:date>2024-06-17T18:23:04Z</dc:date>
    </item>
    <item>
      <title>Re: IAM policy not taking effect</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248529#M32799</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/50323"&gt;@JamesD09&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;have you checked with the "effective policies" tool whether there isn't another access right that would extend this policy and make this limitation ineffective?&lt;BR /&gt;You also have to check that no RBAC permission gives the user&amp;nbsp;more rights over logs than you'd expect.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2024 09:46:14 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/IAM-policy-not-taking-effect/m-p/248529#M32799</guid>
      <dc:creator>GerardJ</dc:creator>
      <dc:date>2024-06-18T09:46:14Z</dc:date>
    </item>
  </channel>
</rss>

