on 25 Sep 2025 10:44 PM
*Use a table of contents for longer articles.
The security team is reporting an insufficient rate limiting on the Dynatrace Managed user login page, which allowed multiple password attempts and potential brute-force attacks.
| Issue | Solution | Tasks | Alternatives |
| The user login page requires a username and a password for login. After three failed attempts, the system enforces a one-minute delay, allowing approximately 180 attempts per hour. |
Dynatrace Managed enforces strong password complexity rules, making brute-force attacks highly impractical. - See below for more information. |
Enforce strong password policies and follow best practices. | Consider integrating SSO and leveraging the additional security offered by the Identity Provider. |
Dynatrace Managed enforces strong security measures to protect user authentication. Dynatrace has implemented password complexity rules that require a combination of uppercase, lowercase, digits, and special characters. These measures significantly reduce the feasibility of brute-force attacks.
Based on these rules, even without additional rate-limiting mechanisms, it would take an estimated 200 years to successfully brute-force a password with a minimum requirement.
For more details, refer to the official documentation:
Password Complexity Rules