on 08 Oct 2026 03:32 PM
Dynatrace AWS monitoring relies on AWS APIs and Amazon CloudWatch to discover AWS resources and collect monitoring data.
AWS monitoring can fail even when the Dynatrace IAM role has the expected permissions. AWS Organizations can still block required API actions through a Service Control Policy, also known as an SCP.
This article explains how to identify an SCP-related authorization failure, verify the restriction in AWS, and validate Dynatrace AWS monitoring after the restriction is corrected.
Dynatrace AWS monitoring data is missing or incomplete even though:
Depending on the denied AWS API action, the issue can affect AWS resource discovery, CloudWatch metrics, integration health, or other AWS monitoring data.
The following are sanitized examples of errors that can occur. The exact error message may vary:
An error occurred (AccessDenied) when calling the DescribeInstances operation:
User:
arn
sts::123456789012:assumed-role/DynatraceMonitoringRole
is not authorized to perform:
ec2:DescribeInstances
with an explicit deny in a service control policy
Another example:
Access denied - explicit deny in SCP
Action:
cloudwatch:GetMetricData
Status:
Denied by Organizations policy
If the error references Service Control Policy, SCP, explicit deny, or AWS Organizations, the request may be blocked by AWS Organizations before Dynatrace can collect the required monitoring data.
Identify and record:
Confirm whether the error contains any of the following:
Service Control Policy
SCP
explicit deny
AWS Organizations
Review AWS CloudTrail Event history for related AccessDenied events.
Confirm:
The AWS re:Post article Troubleshoot SCPs explicit deny errors in AWS Organizations recommends using AWS CloudTrail Event history to confirm whether an SCP denied the request.
Work with the AWS administration, cloud-governance, or security team to review:
IAM permissions are only part of the authorization path. An IAM role may have the expected permissions, but AWS can still deny the request if an applicable SCP blocks the required action.
If monitoring works in one AWS Region but fails in another, verify:
Verify that Dynatrace can assume the configured AWS monitoring role successfully.
If role assumption succeeds but a later AWS API request receives an explicit SCP denial, investigate the applicable Service Control Policies rather than only reviewing the role’s IAM permissions.
Service Control Policies are managed through AWS Organizations. If the required AWS API action is denied by an SCP, the policy must be reviewed and corrected by the AWS administration, cloud-governance, or security team.
Dynatrace cannot modify or override policies enforced by AWS Organizations.
After the AWS team reviews and corrects the restriction:
Classic AWS monitoring with ActiveGate
For Classic AWS monitoring environments that rely on ActiveGate configuration, verify that the required AWS monitoring configuration is present in the custom.properties file. Regions are delineated by semicolons, no spaces are needed.
Example:
.properties
[aws_monitoring]
aws_monitoring_enabled = true
aws_client_regions = "us-east-1;us-east-2"
Settings stored in custom.properties override the corresponding settings in config.properties.
If custom.properties is updated, restart the affected ActiveGate service so that the configuration can be reloaded.
New AWS Monitoring Connections
For new AWS Monitoring Connections, confirm that all required AWS Regions are included during connection setup.
If a Region is omitted from the monitoring connection or restricted through an SCP, Dynatrace may not be able to collect monitoring data from resources in that Region.
If CloudTrail continues to report SCP-related AccessDenied events, work with the internal AWS administration team or engage AWS Support.
This may be necessary when:
If the AWS-side SCP restrictions have been reviewed or corrected and monitoring still does not work as expected, create a chat or open a Dynatrace Support case.
Mention that you reviewed this article and include:
Providing this information helps separate an AWS authorization restriction from a remaining Dynatrace configuration or data-collection issue.
📖 Service control policies (SCPs) - AWS Organizations
📖 SCP evaluation - AWS Organizations
📖 Troubleshoot SCPs explicit deny errors in AWS Organizations | AWS re:Post
📖 Troubleshoot explicit deny errors in AWS Organizations | AWS re:Post
📖 Amazon Web Services monitoring — Dynatrace Docs
Configuration properties and parameters of ActiveGate — Dynatrace Docs
AWS: How can we configure a single AWS account to use two ActiveGates to monitor separate regions?