Add IAM Users on Autonomous AI Database
To add IAM users to allow access to Autonomous AI Database, map database global users to IAM groups or users with
CREATE USER or ALTER USER statements (with
IDENTIFIED GLOBALLY AS clause).
The authorization of IAM users to an Autonomous AI Database instance works by mapping IAM global users (schemas) to IAM users (exclusive mapping) or IAM groups (shared schema mapping).
To authorize IAM users on an Autonomous AI Database instance:
Note:
Database users that are notIDENTIFIED GLOBALLY can continue to
login as before, even when the Autonomous AI Database is enabled for IAM authentication.
To exclusively map a local IAM user to an Oracle Database Global User:
-
Log in as the ADMIN user to the database that is enabled to use IAM (the ADMIN user has the required
CREATE USERandALTER USERsystem privileges that you need for these steps). -
Create a mapping between the Autonomous AI Database user (schema) with
CREATE USERorALTER USERstatements and include theIDENTIFIED GLOBALLY ASclause, specifying the IAM local IAM user name.For example, to create a new database global user named
peter_fitchand map this user to an existing local IAM user namedpeterfitch:CREATE USER peter_fitch IDENTIFIED GLOBALLY AS 'IAM_PRINCIPAL_NAME=peterfitch'The following example shows how to create the user by specifying a non-default domain,
sales_domain:CREATE USER peter_fitch2 IDENTIFIED GLOBALLY AS 'IAM_PRINCIPAL_NAME=sales_domain/peterfitch';