Dynatrace
Connect Dynatrace to Ploy to see everyone in your Dynatrace account, including people who have been invited but have not signed up yet, and which user groups each person belongs to. Ploy can also invite people to the account, remove them from it, and add or remove them from user groups.
This integration is in beta
The Dynatrace integration is in beta. It was built from Dynatrace's documented Account Management API and has not yet been run against a live Dynatrace account, so some behaviour may differ from what is described here until it has.
The first step of setup is a consent checkbox. Ticking it lets Ploy send redacted error data to its own monitoring when a call to Dynatrace fails. Redacted means secrets, tokens and personal details are removed before anything is stored. Ploy uses it only to fix problems with the integration. You need to tick it to continue.
What Ploy reads
Every user in the connected Dynatrace account, with their email address and name. Invited users who have not signed up yet are shown as pending.
The account itself, so several Dynatrace accounts connected to one Ploy organisation stay separate.
Every user group, and who belongs to it. Groups synced from your identity provider over SCIM or SAML say so in their description.
Service users, the permissions and policies each group grants, environments and the audit log are not scanned yet.
What Ploy can change
Invite a person to the account by email. They show as pending until they accept the invitation. Inviting someone who already has a user counts as done.
Remove a person from the account. Removing someone who is already gone counts as done. Dynatrace has no suspend, so removal is the only way to take access away.
Add or remove a person from a user group, from the group's page in Ploy. Adding someone to a group never changes their other groups.
Before you start
You need an account administrator in Dynatrace Account Management, and two things from it:
Your account UUID, the identifier of your Dynatrace account in Account Management.
An OAuth client. In Account Management, go to Identity & access management, then OAuth clients, and create a client with the
account-idm-readpermission (to read users, groups and group members) and theaccount-idm-writepermission (to invite and remove people and change group membership). Copy the client ID and the client secret. Dynatrace shows the secret only once.
Connect Dynatrace
In Ploy, open Integrations and choose Dynatrace.
Tick the beta consent checkbox.
Enter your account UUID, the OAuth client ID and the client secret.
Select Test to check the details. Ploy reads your account's users with the client to confirm it works.
Save the connection. The first scan starts straight away.
To connect another Dynatrace account, add another Dynatrace connection.
Troubleshooting
Dynatrace rejected that OAuth client: check the client ID and secret were copied in full and that the client still exists.
Dynatrace refused to list users: the client is missing the
account-idm-readoraccount-idm-writepermission.Dynatrace could not find that account: check the account UUID.