Dynatrace - SSO configuration

Dynatrace - SSO configuration

Idea
This documentation has been tested and approved by Kelvin Zero's team
This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Dynatrace using MPAS. SSO simplifies user authentication by allowing access to multiple applications with a single set of credentials. This integration enhances security and improves user experience across your organization
Warning
To set up Multi-Pass with  Dynatrace, ensure you meet the following requirements:
- Dynatrace admin rights
- MPAS Admin rights
- Make sure that all users intended to use SSO in Dynatrace are registered in your IdP and have the necessary permissions to access Dynatrace.
Important: Custom elements in URLs (like realm names) are case sensitive. Make sure to match the exact casing from your environment.



Dynatrace - SSO configuration




Step 1 - Dynatrace Configuration

  1. Log into the Dynatrace Administration Portal.
  2. Navigate to Identity & Access Management, SAML Configuration.

  1. Click New Configuration

  1. Select Account Federation and click Next.

  1. Name the configuration Multi-Pass.
  2. Click Generate SP Metadata and save the XML file locally.


Step 2 - Multi-Pass Configuration

  1. Open Multi-Pass Dashboard
  2. Select your tenant

  1. On the left side, click on Integrations
  2. then click on Applications.
  3. Choose SAML under Custom Integrations.

  1. Upload the Dynatrace SP metadata you downloaded earlier.
  1. Verify that the NameID Policy Format is set to email.
SAML — Form values (Multi-Pass)
FieldValue
Client ID (= SP Entity ID)https://sso.dynatrace.com/identity-federation/federation/<RANDOM_STRING>
NameDynatrace
DescriptionDynatrace SSO integration
Assertion Consumer Service (ACS) URLhttps://sso.dynatrace.com/identity-federation/sp/consumer/account/<RANDOM_STRING>/federation/<RANDOM_STRING>
NameID Policy Formatemail
  1. Click Add Integration.
  2. Download the Tenant XML Data and save it locally (to upload into Dynatrace later).
  1. Open Advanced Console

  1. Click on Clients.
  2. Search for Dynatrace and verify the settings below.
General settings
FieldValue
Client IDhttps://sso.dynatrace.com/identity-federation/federation/<RANDOM_STRING>
NameDynatrace
DescriptionDynatrace SSO integration
Always Display in UION

Access settings
FieldValue
Home URL (IdP-initiated)https://ca.auth.kzero.com/realms/<TENANT_NAME>/protocol/saml/clients/<APP_NAME>
Valid Redirect URIs (ACS)https://sso.dynatrace.com/identity-federation/sp/consumer/account/<RANDOM_STRING>/federation/<RANDOM_STRING>
IDP-Initiated SSO URL Name<APP_NAME>
Valid post logout redirect URIshttps://sso.dynatrace.com/identity-federation/sp/consumer/account/<RANDOM_STRING>/federation/<RANDOM_STRING>

SAML Capabilities
SettingValue
Name ID Formatemail
Force Name ID FormatON
Force POST BindingON
Include AuthnStatementON

Signature & Encryption
SettingValue
Sign DocumentsON
Sign AssertionsON

Step 3 - Complete Dynatrace SP Configuration

  1. In Dynatrace, return to your SAML configuration wizard.
  2. Upload the Tenant XML Metadata file from Multi-Pass.
  3. Validate by signing in with a Multi-Pass test account.
  4. Under Scope Assignment, select Allow users from all other domains to authenticate via your IdP.
  1. Toggle Enable SSO ON and click Complete Configuration.
    • Related Articles

    • SAML SSO Integration Guide

      This guide provides an overview of how to configure SAML Single Sign-On (SSO) between Multi-Pass and a third-party Service Provider (SP). Multi-Pass acts as the Identity Provider (IdP) in this federation model. Multi-Pass is working on SCIM support ...
    • Notion - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...
    • Vanta - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Vanta using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • Addigy - SSO configuration

      This documentation has been tested and approved by Kelvin Zero's team This documentation provides a step-by-step guide to setting up Single Sign-On (SSO) for Addigy using MPAS. SSO simplifies user authentication by allowing access to multiple ...
    • ZoomInfo - SSO configuration

      Please note that this application has not been formally tested by Kelvin Zero Inc. It is provided solely as a reference guide. If you encounter any issues, kindly submit a ticket directly through the support desk. This documentation provides a ...