Dynatrace SAML Integration in Cloud Environment

This document explains how to implement Monosign with Dynatrace. It covers Single Sign-On using SAML, where Monosign acts as the Identity Provider (IdP) and Dynatrace as the Service Provider (SP).

Instructions

This documentation contains 5 main steps for integration.

  1. Creating an Application on Monosign

  2. Configuration Single Sign-On for Dynatrace

  3. Assign a user to the Dynatrace application

  4. Sign In Test

  5. Troubleshooting

1- Creating an Application on Monosign

Create your application on Monosign and configure your access policy. Once you create, click "Keys" and add a new Access Key for SAML Key for access.

image-20261008-062522.png
image-20261007-112749.png
image-20261008-061019.png


Import the metadata XML file from the Dynatrace configuration settings.
(Heading 2 – Image 3 – “Download SP Metadata” button)

image-20261007-145620.png


We will need this information while we configure the Dynatrace federation.

Property

Value

Options

Key Type

SAML

Rest API, OAuth 2.0, JWT, OIDC/OpenID, SAML, RADIUS, Access Gateway, LDAP, AuthN/Z Server

Expiration

Lifetime

Lifetime or Specific Date/Time - By Default Lifetime is Enabled.

Configuration details for the Dynatrace application are provided as follows:

Change ACS (Assertion Consumer Url), Entity Id, NameId Format, Name Id and Extra Attributes. Use the values shown on the Dynatrace federation screen (see step 2).

Property

Value

Assertion Consumer Url

<ACS_URL_FROM_DYNATRACE>

Entity Id

<SP_ENTITY_ID_FROM_DYNATRACE>

NameId Format

Email Address (urn:oasis:names:tc:SAML:1.1:nameid-format:emailAddress)

Name Id

Email

Extra Attributes

email : {{Email}} firstname : {{FirstName}} lastname : {{LastName}} <GROUP_ATTRIBUTE_NAME> : group name (see Dynatrace group mapping below)

⚠️ Dynatrace compares the e-mail address entered on the sign-in screen with the identity returned by the IdP. Name Id must be the user's e-mail address, not the username, otherwise the login is rejected with a 400 error (see Troubleshooting).

To ensure that the application has access to user groups, follow these steps:

  1. If the application hasn't been configured yet, click the "Edit" option for the application.

  2. In the application settings, navigate to the "Source, Provider, and Profile" tab.

  3. Configure the "User Access Type" and "User Group Access Type" as "Only Assigned Users."

2- Configuration Single Sign-On for Dynatrace

In Dynatrace, open Account Management and start a new SAML federation. When asked for the federation type, select Account federation.

Federation type

Scope

Account federation

The whole Dynatrace account (all environments). Recommended for a single account.

Environment federation

A single environment only.

Global federation

Based on the e-mail domain, applies across multiple accounts.

Enter the IdP details from the Monosign application key created in step 1 (Sign On Service, Logout Service and View Certificate / Download Certificate), or upload the Monosign SAML metadata if Dynatrace asks for it.

image-20261008-061619.png
image-20261007-114613.png
image-20261008-062420.png
image-20261008-062232.png
image-20261007-114532.png

Dynatrace creates users on their first successful SAML login, but permissions are granted through groups. Create a group under Identity & access management > Groups, assign a policy to it and scope the policy to the environment the users should reach.

Setting

Purpose

Group

Container for permissions. The group name must match the value sent in the group attribute of the SAML assertion exactly.

Policy

Defines what the group members can do. A group without a policy gives the user no access.

Policy scope

The environment (or account) the policy applies to.

If the group attribute is not sent by Monosign, either add the user to a group manually from Account Management > Users after the first login, or grant the permission to the built-in Default group with all users as described below.

Dynatrace Permission Settings

A user created by SAML has no permissions until a group with a policy applies to them. Without one, the first login ends with a 403 You don't have permission to view this page error. The quickest way to give every federated user access is to attach a policy to the built-in Default group with all users (group type ALL_USERS). Every user in the account is a member of this group automatically, so no group attribute has to be sent by Monosign.

Open the default group

  1. In Dynatrace, open the menu in the top-left corner and go to Identity & access management > Group management (marked 1 in the screenshot).

  2. In the group list, click Default group with all users (marked 2). The other built-in groups (Account Admins, Account Viewers, Environment Admins, Environment Users, Environment Professionals) can be used for role-based access, see the note below.

image-20261008-061705.png

Add the permission

  1. On the View group Default group with all users page, find the Permissions section and click the + Permission button on the right side.

  2. In the permission list, select the Standard User policy and set its scope to your Dynatrace environment.

  3. Save. The Permissions table now shows the new entry, as in the screenshot below.

image-20261008-061854.png


Field

Value

Group

Default group with all users (ALL_USERS)

Permission

Standard User

Permission Type

POLICY

Scope

Environment (<ENVIRONMENT_ID>)

Scope of the default group: a policy on Default group with all users applies to every user in the Dynatrace account, not only to Monosign users. Because access is already restricted on the Monosign side with Only Assigned Users (see step 1), this is acceptable when all assigned users should get the same level of access. For different roles or customer-specific separation, use dedicated groups instead.

Role-based access (optional): create separate groups (for example an admin group and a read-only group), attach the matching policy to each (for example Environment Admins or Standard User) and send the group name from Monosign in the group attribute. The group name in Dynatrace must match the attribute value exactly, including case.

After saving the permission, ask the user to sign out of Dynatrace and sign in again. Permissions are only evaluated at login.

3- Assign a user to the Dynatrace application

Please follow below instructions on how to assign a user to the Dynatrace application. Give the user access from the application's Access tab, and make sure their Monosign profile has Email filled in. The e-mail must be exactly the address the user types on the Dynatrace sign-in screen.

image-20261007-205716.png
image-20261007-205910.png


4- Sign In Test

Now try to login. Navigate to the Dynatrace sign-in page and enter your e-mail address. You will be redirected to the Monosign login page. Log in passwordless with your QR code or with your username and password.

Once authenticated, you will be redirected back to Dynatrace as the mapped user. If the user does not belong to a group with a policy yet, Dynatrace shows a 403 page; add the user to the group (or apply the permission to the default group, see Dynatrace Permission Settings) and sign in again.


image-20261007-204047.png
image-20261007-120022.png
image-20261007-204104.png
image-20261008-063031.png


5- Troubleshooting

Error

Cause

Solution

400 Request denied: Your IdP returned different user root than user root@example.com you entered into Dynatrace

Monosign sends the username (for example root) as NameID instead of the e-mail address.

Set NameId Format to Email Address and Name Id to Email. Make sure the user's e-mail in Monosign is filled in and identical to the address entered in Dynatrace. Log out of the IdP session and try again.

403 You don't have permission to view this page ([empty email address])

The e-mail attribute is empty in the assertion and/or the user is not a member of any group with a policy.

Add the email extra attribute in Monosign. In Dynatrace, add the Standard User policy (environment scope) to the Default group with all users, or to a dedicated group the user belongs to (see Dynatrace Permission Settings), then sign out and sign in again.