<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>article Security Concern: Password Complexity and Rate Limiting for User Login in Troubleshooting</title>
    <link>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-Password-Complexity-and-Rate-Limiting-for-User/ta-p/286276</link>
    <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Self Service Summary&lt;/H1&gt;
&lt;P&gt;The security team is reporting an insufficient rate limiting on the Dynatrace Managed user login page, which allowed multiple password attempts and potential brute-force attacks.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Tasks&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Alternatives&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;The user login page requires a username and a password for login. After three failed attempts, the system enforces a one-minute delay, allowing approximately 180 attempts per hour.&lt;/TD&gt;
&lt;TD width="25%"&gt;
&lt;P&gt;Dynatrace Managed enforces strong password complexity rules, making brute-force attacks highly impractical. - See below for more information.&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="25%"&gt;Enforce strong password policies and follow best practices.&lt;/TD&gt;
&lt;TD width="25%"&gt;Consider integrating SSO and leveraging the additional security offered by the Identity Provider.&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;Explanation&lt;/H1&gt;
&lt;P&gt;Dynatrace Managed enforces strong security measures to protect user authentication. Dynatrace has implemented &lt;STRONG&gt;password complexity rules&lt;/STRONG&gt; that require a combination of uppercase, lowercase, digits, and special characters. These measures significantly reduce the feasibility of brute-force attacks.&lt;/P&gt;
&lt;P&gt;Based on these rules, even without additional rate-limiting mechanisms, it would take an estimated &lt;STRONG&gt;200 years&lt;/STRONG&gt; to successfully brute-force a password with a minimum requirement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more details, refer to the official documentation:&lt;BR /&gt;&lt;A class="fui-Link ___w5et180 f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv f1mo0ibp fjoy568 ff5ikls f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a" tabindex="0" href="https://docs.dynatrace.com/managed/shortlink/managed-password-complexity-rules" target="_blank" rel="noopener noreferrer" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Password Complexity Rules&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Recommendations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;Share the official documentation with your security team to confirm compliance with best practices.&lt;/LI&gt;
&lt;LI&gt;Ensure that all users follow the enforced password complexity requirements.&lt;/LI&gt;
&lt;LI&gt;Regularly review and rotate passwords as part of your organization’s security policy.&lt;/LI&gt;
&lt;LI&gt;Consider integrating SSO for additional security from the Identity Provider.&lt;/LI&gt;
&lt;LI&gt;If additional security features are desired, such as CAPTCHA or progressive delays, submit a product idea:&lt;BR /&gt;&lt;A href="https://community.dynatrace.com/t5/Community-user-guide/Product-ideas/ba-p/159825" target="_blank" rel="noopener"&gt;Dynatrace Product Ideas&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
    <pubDate>Thu, 25 Sep 2025 21:44:31 GMT</pubDate>
    <dc:creator>jonghpark</dc:creator>
    <dc:date>2025-09-25T21:44:31Z</dc:date>
    <item>
      <title>Security Concern: Password Complexity and Rate Limiting for User Login</title>
      <link>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-Password-Complexity-and-Rate-Limiting-for-User/ta-p/286276</link>
      <description>&lt;P&gt;&lt;LI-TOC indent="15" liststyle="disc" maxheadinglevel="2"&gt;&lt;/LI-TOC&gt;&lt;/P&gt;
&lt;DIV class="lia-message-template-content-zone"&gt;
&lt;P&gt;*&lt;EM&gt;Use a table of contents for longer articles.&amp;nbsp;&lt;/EM&gt;&lt;/P&gt;
&lt;H1&gt;Self Service Summary&lt;/H1&gt;
&lt;P&gt;The security team is reporting an insufficient rate limiting on the Dynatrace Managed user login page, which allowed multiple password attempts and potential brute-force attacks.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Issue&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Solution&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Tasks&lt;/STRONG&gt;&lt;/TD&gt;
&lt;TD width="25%"&gt;&lt;STRONG&gt;Alternatives&lt;/STRONG&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;TR&gt;
&lt;TD width="25%"&gt;The user login page requires a username and a password for login. After three failed attempts, the system enforces a one-minute delay, allowing approximately 180 attempts per hour.&lt;/TD&gt;
&lt;TD width="25%"&gt;
&lt;P&gt;Dynatrace Managed enforces strong password complexity rules, making brute-force attacks highly impractical. - See below for more information.&lt;/P&gt;
&lt;/TD&gt;
&lt;TD width="25%"&gt;Enforce strong password policies and follow best practices.&lt;/TD&gt;
&lt;TD width="25%"&gt;Consider integrating SSO and leveraging the additional security offered by the Identity Provider.&amp;nbsp;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;H1&gt;&amp;nbsp;&lt;/H1&gt;
&lt;H1&gt;Explanation&lt;/H1&gt;
&lt;P&gt;Dynatrace Managed enforces strong security measures to protect user authentication. Dynatrace has implemented &lt;STRONG&gt;password complexity rules&lt;/STRONG&gt; that require a combination of uppercase, lowercase, digits, and special characters. These measures significantly reduce the feasibility of brute-force attacks.&lt;/P&gt;
&lt;P&gt;Based on these rules, even without additional rate-limiting mechanisms, it would take an estimated &lt;STRONG&gt;200 years&lt;/STRONG&gt; to successfully brute-force a password with a minimum requirement.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For more details, refer to the official documentation:&lt;BR /&gt;&lt;A class="fui-Link ___w5et180 f2hkw1w f3rmtva f1ewtqcl fyind8e f1k6fduh f1w7gpdv f1mo0ibp fjoy568 ff5ikls f1s184ao f1mk8lai fnbmjn9 f1o700av f13mvf36 f1cmlufx f9n3di6 f1ids18y f1tx3yz7 f1deo86v f1eh06m1 f1iescvh fhgqx19 f1olyrje f1p93eir f1nev41a" tabindex="0" href="https://docs.dynatrace.com/managed/shortlink/managed-password-complexity-rules" target="_blank" rel="noopener noreferrer" data-tabster="{&amp;quot;restorer&amp;quot;:{&amp;quot;type&amp;quot;:1}}"&gt;Password Complexity Rules&lt;/A&gt;&lt;/P&gt;
&lt;H1&gt;Recommendations&lt;/H1&gt;
&lt;OL&gt;
&lt;LI&gt;Share the official documentation with your security team to confirm compliance with best practices.&lt;/LI&gt;
&lt;LI&gt;Ensure that all users follow the enforced password complexity requirements.&lt;/LI&gt;
&lt;LI&gt;Regularly review and rotate passwords as part of your organization’s security policy.&lt;/LI&gt;
&lt;LI&gt;Consider integrating SSO for additional security from the Identity Provider.&lt;/LI&gt;
&lt;LI&gt;If additional security features are desired, such as CAPTCHA or progressive delays, submit a product idea:&lt;BR /&gt;&lt;A href="https://community.dynatrace.com/t5/Community-user-guide/Product-ideas/ba-p/159825" target="_blank" rel="noopener"&gt;Dynatrace Product Ideas&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 25 Sep 2025 21:44:31 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Troubleshooting/Security-Concern-Password-Complexity-and-Rate-Limiting-for-User/ta-p/286276</guid>
      <dc:creator>jonghpark</dc:creator>
      <dc:date>2025-09-25T21:44:31Z</dc:date>
    </item>
  </channel>
</rss>

