06 Jan 2019 11:36 AM - last edited on 10 Dec 2021 11:09 AM by MaciejNeumann
Dear All,
Can we have a user level permissions for an environment?
The use case is that we integrated with LDAP and imported a group of users who will manage the Dynatrace Managed Environments but with different tasks e.g. one of them will have the rights to Change monitoring settings and second will only Download & install OneAgent and vice versa.
Regards,
Babar
06 Jan 2019 01:06 PM
I’ve never had integrated ldap working yet by you should be able to see those groups and add proper roles to them (that can be defined by you).
Sebastian
06 Jan 2019 01:25 PM
Hello @sebastian k.
Thank you for your reply. We imported the group after LDAP integration but the challenge is to assign specific rights/permissions of users who are part of that group because currently permissions are available only on group level.
Looking for more granular control.
Regards,
Babar
06 Jan 2019 01:39 PM
I think you will have to ask client for creating some extra ldap groups for you. This is what we are making in Appmon for example. Users than are added to specific groups on ldap side and this is how client can than handle permissions without touching Dynatrace. This is also what we are recommending for Dynatrace. I think on user level there is only option to assign to groups.
Sebastian
06 Jan 2019 02:11 PM
Hello @sebastian k.
This can be a very tedious and unacceptable by customer because this flexibility should be on the product side instead of making AD groups for each respective user.
In the AppMon we have another arrangement for local users and groups to map the LDAP groups.
Regards,
Babar
06 Jan 2019 02:34 PM
I agree, for now I think the only way is posting RFE because permission management in Dynatrace is not as flexible as in Appmon.
Sebastian
07 Jan 2019 05:39 AM
Hello @sebastian k.
Agree. I will post an RFE to have some votes for the consideration of this idea.
Regards,
Babar