<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Security Concern: ActiveGate Service Account dtuserag and Permissions in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-ActiveGate-Service-Account-dtuserag-and/ta-p/286265</link>
    <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Self Service Summary&lt;/H1&gt;
&lt;P&gt;The &lt;CODE&gt;dtuserag&lt;/CODE&gt; account is a local, unprivileged Linux user created by the Dynatrace ActiveGate installer to run its services securely. While it cannot be used for direct login, it has access to specific configuration directories with restricted permissions that typically require root access.&lt;/P&gt;
&lt;P&gt;Security teams may raise concerns because this account operates outside standard user management workflows and may not be visible in centralized monitoring. Additionally, the operating system must support high resource limits for this user, at least &lt;STRONG&gt;500,000 open files&lt;/STRONG&gt; and &lt;STRONG&gt;20,000 processes,&amp;nbsp;&lt;/STRONG&gt;to ensure proper functionality. These requirements may trigger alerts or scrutiny during audits or vulnerability scans.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Tasks&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Alternatives&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="25%" height="29px"&gt;Security team flagged &lt;CODE&gt;dtuserag&lt;/CODE&gt; for elevated permissions or lack of visibility&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;Explain that &lt;CODE&gt;dtuserag&lt;/CODE&gt; is a dedicated unprivileged local Linux user created by the ActiveGate installer - See below for more information.&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;Share official documentation and explain to your Security team.&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;SPAN&gt;Submit a support ticket if you need additional details or you face a different scenario&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Explanation&lt;/H1&gt;
&lt;P&gt;The &lt;CODE&gt;dtuserag&lt;/CODE&gt; account is a &lt;STRONG&gt;service account&lt;/STRONG&gt; used by Dynatrace ActiveGate on Linux systems. &lt;BR /&gt;According to Dynatrace documentation:&amp;nbsp;&lt;EM&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#service-account" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#service-account&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“All ActiveGate services are by default running as dedicated unprivileged user &lt;CODE&gt;dtuserag&lt;/CODE&gt;. The only exception is &lt;CODE&gt;dynatraceautoupdater&lt;/CODE&gt;, which requires root privileges. If the user &lt;CODE&gt;dtuserag&lt;/CODE&gt; does not already exist in the system, the installer will create it.”&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This account is &lt;STRONG&gt;not intended for interactive login or administrative tasks&lt;/STRONG&gt;. It exists solely to run ActiveGate services securely and with minimal privileges.&amp;nbsp;The &lt;STRONG&gt;&lt;CODE&gt;dynatraceautoupdater&lt;/CODE&gt;&lt;/STRONG&gt; component may require elevated privileges during installation or updates. You will find all the services related to ActiveGate in this documentation:&amp;nbsp;&lt;A href="https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#services" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#services&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Recommendations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;Share the official documentation with your security team.&lt;/LI&gt;
&lt;LI&gt;Confirm that &lt;CODE&gt;dtuserag&lt;/CODE&gt; is used only by ActiveGate services and not for manual operations.&lt;/LI&gt;
&lt;LI&gt;Please reach out to Dynatrace Support for further clarification or other scenarios. &lt;BR /&gt;When opening a support ticket, please mention that this article was used and provide the following in the ticket:
&lt;DIV class="p-client_container"&gt;
&lt;DIV class="p-ia4_client_container"&gt;
&lt;DIV class="p-ia4_client p-ia4_client--with-search-in-top-nav p-ia4_client--workspace-switcher-rail-visibletest p-ia4_client--sidebar-wide p-ia4_client--narrow-feature-on"&gt;
&lt;DIV class="p-client_workspace_wrapper" role="tabpanel" aria-label="Dynatrace"&gt;
&lt;DIV class="p-client_workspace" role="tabpanel" aria-label="DMs"&gt;
&lt;DIV class="p-client_workspace__layout"&gt;
&lt;DIV class="active-managed-focus-container" role="none"&gt;
&lt;DIV class="p-view_contents p-view_contents--primary" tabindex="-1" role="dialog" aria-label="Conversation with Anton Konikov"&gt;
&lt;DIV class="tabbed_channel__Abx5r"&gt;
&lt;DIV class="tabbed_channel__Abx5r"&gt;
&lt;DIV class="channel_tab_panel__zJ5Bt c-tabs__tab_panel c-tabs__tab_panel--active c-tabs__tab_panel--full_height" role="none" data-qa="tabs_content_container"&gt;
&lt;DIV class="p-file_drag_drop__container"&gt;
&lt;DIV class="p-workspace__primary_view_body"&gt;
&lt;DIV class="p-message_pane p-message_pane--classic-nav p-message_pane--scrollbar-float-adjustment p-message_pane--with-bookmarks-bar" data-qa="message_pane"&gt;
&lt;DIV role="presentation"&gt;
&lt;DIV class="c-virtual_list c-virtual_list--scrollbar c-message_list c-message_list--floating c-message_list--dark c-scrollbar c-scrollbar--fade" role="presentation"&gt;
&lt;DIV class="c-scrollbar__hider" role="presentation" data-qa="slack_kit_scrollbar"&gt;
&lt;DIV class="c-scrollbar__child" role="presentation"&gt;
&lt;DIV class="c-virtual_list__scroll_container" tabindex="-1" role="list" data-qa="slack_kit_list" aria-label="Anton Konikov (direct message, active)"&gt;
&lt;DIV id="1734101723.604509" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1734101723.604509"&gt;
&lt;DIV class="c-message_kit__background p-message_pane_message__message c-message_kit__message p-message_pane_message__message--last" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet p-rich_text_list--nested" data-stringify-type="unordered-list" data-list-tree="true" data-indent="0" data-border="1" data-border-radius-top-cap="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="1"&gt;Activegate Support Archive - This will contain the version and operating system information.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Tue, 07 Oct 2025 09:20:20 GMT</pubDate>
    <dc:creator>jonghpark</dc:creator>
    <dc:date>2025-10-07T09:20:20Z</dc:date>
    <item>
      <title>Security Concern: ActiveGate Service Account dtuserag and Permissions</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-ActiveGate-Service-Account-dtuserag-and/ta-p/286265</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Self Service Summary&lt;/H1&gt;
&lt;P&gt;The &lt;CODE&gt;dtuserag&lt;/CODE&gt; account is a local, unprivileged Linux user created by the Dynatrace ActiveGate installer to run its services securely. While it cannot be used for direct login, it has access to specific configuration directories with restricted permissions that typically require root access.&lt;/P&gt;
&lt;P&gt;Security teams may raise concerns because this account operates outside standard user management workflows and may not be visible in centralized monitoring. Additionally, the operating system must support high resource limits for this user, at least &lt;STRONG&gt;500,000 open files&lt;/STRONG&gt; and &lt;STRONG&gt;20,000 processes,&amp;nbsp;&lt;/STRONG&gt;to ensure proper functionality. These requirements may trigger alerts or scrutiny during audits or vulnerability scans.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Tasks&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;STRONG&gt;Alternatives&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="25%" height="29px"&gt;Security team flagged &lt;CODE&gt;dtuserag&lt;/CODE&gt; for elevated permissions or lack of visibility&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;Explain that &lt;CODE&gt;dtuserag&lt;/CODE&gt; is a dedicated unprivileged local Linux user created by the ActiveGate installer - See below for more information.&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;Share official documentation and explain to your Security team.&lt;/TD&gt;
&lt;TD width="25%" height="29px"&gt;&lt;SPAN&gt;Submit a support ticket if you need additional details or you face a different scenario&lt;/SPAN&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;H1&gt;Explanation&lt;/H1&gt;
&lt;P&gt;The &lt;CODE&gt;dtuserag&lt;/CODE&gt; account is a &lt;STRONG&gt;service account&lt;/STRONG&gt; used by Dynatrace ActiveGate on Linux systems. &lt;BR /&gt;According to Dynatrace documentation:&amp;nbsp;&lt;EM&gt;&lt;A href="https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#service-account" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#service-account&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;“All ActiveGate services are by default running as dedicated unprivileged user &lt;CODE&gt;dtuserag&lt;/CODE&gt;. The only exception is &lt;CODE&gt;dynatraceautoupdater&lt;/CODE&gt;, which requires root privileges. If the user &lt;CODE&gt;dtuserag&lt;/CODE&gt; does not already exist in the system, the installer will create it.”&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;This account is &lt;STRONG&gt;not intended for interactive login or administrative tasks&lt;/STRONG&gt;. It exists solely to run ActiveGate services securely and with minimal privileges.&amp;nbsp;The &lt;STRONG&gt;&lt;CODE&gt;dynatraceautoupdater&lt;/CODE&gt;&lt;/STRONG&gt; component may require elevated privileges during installation or updates. You will find all the services related to ActiveGate in this documentation:&amp;nbsp;&lt;A href="https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#services" target="_blank" rel="noopener"&gt;https://docs.dynatrace.com/managed/shortlink/activegate-default-settings-linux#services&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Recommendations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;Share the official documentation with your security team.&lt;/LI&gt;
&lt;LI&gt;Confirm that &lt;CODE&gt;dtuserag&lt;/CODE&gt; is used only by ActiveGate services and not for manual operations.&lt;/LI&gt;
&lt;LI&gt;Please reach out to Dynatrace Support for further clarification or other scenarios. &lt;BR /&gt;When opening a support ticket, please mention that this article was used and provide the following in the ticket:
&lt;DIV class="p-client_container"&gt;
&lt;DIV class="p-ia4_client_container"&gt;
&lt;DIV class="p-ia4_client p-ia4_client--with-search-in-top-nav p-ia4_client--workspace-switcher-rail-visibletest p-ia4_client--sidebar-wide p-ia4_client--narrow-feature-on"&gt;
&lt;DIV class="p-client_workspace_wrapper" role="tabpanel" aria-label="Dynatrace"&gt;
&lt;DIV class="p-client_workspace" role="tabpanel" aria-label="DMs"&gt;
&lt;DIV class="p-client_workspace__layout"&gt;
&lt;DIV class="active-managed-focus-container" role="none"&gt;
&lt;DIV class="p-view_contents p-view_contents--primary" tabindex="-1" role="dialog" aria-label="Conversation with Anton Konikov"&gt;
&lt;DIV class="tabbed_channel__Abx5r"&gt;
&lt;DIV class="tabbed_channel__Abx5r"&gt;
&lt;DIV class="channel_tab_panel__zJ5Bt c-tabs__tab_panel c-tabs__tab_panel--active c-tabs__tab_panel--full_height" role="none" data-qa="tabs_content_container"&gt;
&lt;DIV class="p-file_drag_drop__container"&gt;
&lt;DIV class="p-workspace__primary_view_body"&gt;
&lt;DIV class="p-message_pane p-message_pane--classic-nav p-message_pane--scrollbar-float-adjustment p-message_pane--with-bookmarks-bar" data-qa="message_pane"&gt;
&lt;DIV role="presentation"&gt;
&lt;DIV class="c-virtual_list c-virtual_list--scrollbar c-message_list c-message_list--floating c-message_list--dark c-scrollbar c-scrollbar--fade" role="presentation"&gt;
&lt;DIV class="c-scrollbar__hider" role="presentation" data-qa="slack_kit_scrollbar"&gt;
&lt;DIV class="c-scrollbar__child" role="presentation"&gt;
&lt;DIV class="c-virtual_list__scroll_container" tabindex="-1" role="list" data-qa="slack_kit_list" aria-label="Anton Konikov (direct message, active)"&gt;
&lt;DIV id="1734101723.604509" class="c-virtual_list__item" tabindex="0" role="listitem" aria-setsize="-1" data-qa="virtual-list-item" data-item-key="1734101723.604509"&gt;
&lt;DIV class="c-message_kit__background p-message_pane_message__message c-message_kit__message p-message_pane_message__message--last" role="presentation" data-qa="message_container" data-qa-unprocessed="false" data-qa-placeholder="false"&gt;
&lt;DIV class="c-message_kit__hover" role="document" aria-roledescription="message" data-qa-hover="true"&gt;
&lt;DIV class="c-message_kit__actions c-message_kit__actions--above"&gt;
&lt;DIV class="c-message_kit__gutter"&gt;
&lt;DIV class="c-message_kit__gutter__right" role="presentation" data-qa="message_content"&gt;
&lt;DIV class="c-message_kit__blocks c-message_kit__blocks--rich_text"&gt;
&lt;DIV class="c-message__message_blocks c-message__message_blocks--rich_text" data-qa="message-text"&gt;
&lt;DIV class="p-block_kit_renderer" data-qa="block-kit-renderer"&gt;
&lt;DIV class="p-block_kit_renderer__block_wrapper p-block_kit_renderer__block_wrapper--first"&gt;
&lt;DIV class="p-rich_text_block" dir="auto"&gt;
&lt;UL class="p-rich_text_list p-rich_text_list__bullet p-rich_text_list--nested" data-stringify-type="unordered-list" data-list-tree="true" data-indent="0" data-border="1" data-border-radius-top-cap="0"&gt;
&lt;LI data-stringify-indent="0" data-stringify-border="1"&gt;Activegate Support Archive - This will contain the version and operating system information.&lt;/LI&gt;
&lt;/UL&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Tue, 07 Oct 2025 09:20:20 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-ActiveGate-Service-Account-dtuserag-and/ta-p/286265</guid>
      <dc:creator>jonghpark</dc:creator>
      <dc:date>2025-10-07T09:20:20Z</dc:date>
    </item>
  </channel>
</rss>

