<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Restricting Namespace-Level Access for User Groups in SaaS. in Open Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293066#M38467</link>
    <description>&lt;P&gt;We have similar situation and what we did was to create a separate management zone and assign just the necessary namespaces to it. And then we created a role that has view rights over this management zone + one that has edit rights as well, to modify the settings.&lt;BR /&gt;&lt;BR /&gt;By doing this we now have:&lt;BR /&gt;1 MZ that has access to the whole cluster and they see and can edit settings for all namespaces&lt;BR /&gt;1 MZ that contains just some namespaces - with two roles - one read only and one with edin rights over settings.&lt;BR /&gt;&lt;BR /&gt;I hope this helps.&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jan 2026 13:58:50 GMT</pubDate>
    <dc:creator>Georgi_Vuldzhev</dc:creator>
    <dc:date>2026-01-14T13:58:50Z</dc:date>
    <item>
      <title>Restrict namespace-level access for user groups in SaaS</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/292966#M38460</link>
      <description>&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;Hi Team,&lt;BR /&gt;I’m working with a customer who needs to set permissions so that users can view and access details for specific namespaces within a cluster, including their services and related issues.&lt;BR /&gt;For example:&lt;/DIV&gt;
&lt;UL class=""&gt;
&lt;LI&gt;&lt;STRONG&gt;Team 1 (User Group)&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;should only be able to see namespaces 1, 2, and 3.&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Team 2&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;should only be able to see namespaces 4, 5, and 6.&lt;/LI&gt;
&lt;/UL&gt;
&lt;DIV class=""&gt;Additionally, they do not want these teams to see each other’s namespaces or services.&lt;BR /&gt;Is there a way to achieve this in SaaS?&lt;BR /&gt;Regards,&lt;BR /&gt;Vikas A goud&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;
&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 15 Jan 2026 07:46:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/292966#M38460</guid>
      <dc:creator>Vikas_g1997</dc:creator>
      <dc:date>2026-01-15T07:46:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Namespace-Level Access for User Groups in SaaS.</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293007#M38462</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Have a look to &lt;A title="Policy boundaries" href="https://docs.dynatrace.com/docs/shortlink/iam-policy-boundaries" target="_blank" rel="noopener"&gt;Policy boundaries&lt;/A&gt;. You have namespaces examples there.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 07:53:21 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293007#M38462</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-01-14T07:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Namespace-Level Access for User Groups in SaaS.</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293066#M38467</link>
      <description>&lt;P&gt;We have similar situation and what we did was to create a separate management zone and assign just the necessary namespaces to it. And then we created a role that has view rights over this management zone + one that has edit rights as well, to modify the settings.&lt;BR /&gt;&lt;BR /&gt;By doing this we now have:&lt;BR /&gt;1 MZ that has access to the whole cluster and they see and can edit settings for all namespaces&lt;BR /&gt;1 MZ that contains just some namespaces - with two roles - one read only and one with edin rights over settings.&lt;BR /&gt;&lt;BR /&gt;I hope this helps.&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jan 2026 13:58:50 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293066#M38467</guid>
      <dc:creator>Georgi_Vuldzhev</dc:creator>
      <dc:date>2026-01-14T13:58:50Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Namespace-Level Access for User Groups in SaaS.</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293286#M38486</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/71493"&gt;@Georgi_Vuldzhev&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;DIV&gt;&lt;P&gt;Thanks for the suggestion — I was thinking along the same lines. One potential concern, however, is whether users who access the cluster might be able to see or name other namespaces. Could this become an issue?&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 19 Jan 2026 15:36:47 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293286#M38486</guid>
      <dc:creator>Vikas_g1997</dc:creator>
      <dc:date>2026-01-19T15:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Restrict namespace-level access for user groups in SaaS</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293314#M38491</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Maybe &lt;A title="this recent video" href="https://www.youtube.com/watch?v=ChgiqA63hiE" target="_blank" rel="noopener"&gt;this recent video&lt;/A&gt; about Dynatrace IAM might be helpful.&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 09:22:01 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293314#M38491</guid>
      <dc:creator>AntonPineiro</dc:creator>
      <dc:date>2026-01-20T09:22:01Z</dc:date>
    </item>
    <item>
      <title>Re: Restricting Namespace-Level Access for User Groups in SaaS.</title>
      <link>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293326#M38492</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/57336"&gt;@Vikas_g1997&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;In our case we have separate management zones like this&lt;BR /&gt;MZ1: Has access over the whole k8s cluster and sees all namespaces and components below them&lt;BR /&gt;MZ2: Has access to namespaceX, namespaceY, namespace7, etc. and all resources below them&lt;BR /&gt;MZ3: Has access to namespaceA, namespaceB, namespaceC, etc. and all esources belowe them&lt;BR /&gt;&lt;BR /&gt;When users access Dynatrace all of them see the k8s cluster but when they go to the k8s app they only see the namespaces they have access to. This works with the k8s classic app only as it uses MZs. If you want to use the new k8s app you would need to use Segments, I assume it would be something similar.&lt;BR /&gt;&lt;BR /&gt;I hope this answers your question!&lt;BR /&gt;&lt;BR /&gt;All the best,&lt;BR /&gt;Georgi&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jan 2026 12:43:37 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Open-Q-A/Restrict-namespace-level-access-for-user-groups-in-SaaS/m-p/293326#M38492</guid>
      <dc:creator>Georgi_Vuldzhev</dc:creator>
      <dc:date>2026-01-20T12:43:37Z</dc:date>
    </item>
  </channel>
</rss>

