Managing User Accounts and Access

A super user can manage user accounts and access.

About Oracle DBSecCentral Auditor Accounts and Passwords

Learn about Oracle DBSecCentral auditor user accounts and passwords.

There are three types of auditor accounts in Oracle Database Security Central:

Passwords for these accounts need not be unique; however, Oracle recommends that passwords:

Creating Local Auditor Users

Learn how to create user accounts with auditor privileges.

Super auditors can create both super auditor and auditor user accounts.

To create an auditor account in Oracle Database Security Central:

  1. Log in to the Oracle Database Security Central console as a super auditor.

  2. Select Settings.

    The Manage Auditors subtab on the main page is selected by default.

  3. Select Add in the top, right corner.

  4. In the Add Auditor dialog box, select Local DBSecCentral User.

  5. For Local DBSecCentral User, enter the details to create a database auditor.

  6. Enter the newly created Auditor Name.

  7. Select the Auditor Type.

  8. Enter the Password and Re-type Password.

    Oracle Database Security Central does not accept user names with quotation marks, such as "jsmith".

  9. Select Save.

Related Topics

Creating New SSO Users

To create new users for single sign-on (SSO) authentication, you enter the user name and the auditor type.

  1. Log in to the Oracle Database Security Central console as a super auditor.

  2. Select Settings.

  3. On the Manage Auditors subtab, select Add.

  4. In the dialog box, select Single Sign-On.

  5. Enter the SSO user name.

    Allowed characters include uppercase letters, lowercase letters, numbers, and symbols (@.-_!^~+%). The total length of the SSO user name can't exceed 127 characters.

    Note: Though DBSecCentral accepts uppercase and lowercase letters, it will store the user name in only uppercase. Microsoft performs a case-insensitive comparison of the user names.

  6. Select the auditor type, Auditor, Readonly Auditor, or Super Auditor.

  7. Select Save.

Related Topics

Viewing the Status of Auditor User Accounts

Learn how to view the status of auditor user accounts.

As a super auditor, you can view the status of auditor accounts by clicking the Settings The Manage Auditors page lists all auditor and super auditor accounts, their status, and password expiry dates.

Managing User Access to Targets or Groups

Learn to manage user access to targets and target groups.

About Managing User Access

Learn about managing user access.

Super auditors have access to all targets and target groups, and can grant access to specific targets and groups to auditors.

You can control access to targets or groups in two ways:

Controlling Access by User

Learn about controlling user access to targets.

To control which targets or groups are accessible by a user:

  1. Log in to the Oracle Database Security Central console as a super auditor.

  2. Select Settings. The Manage Auditors page displays existing users and the targets or groups to which they have access.

  3. Select the name of the user account that you want to modify.

    The Modify Auditor page appears.

  4. In the Targets & Target Groups section:

    1. Select the access rights to which you want to grant or revoke for this user. You can also search for the access rights in the field under Targets & Target Groups.

    2. Choose the access rights in the Available column and move them to the Selected column, to grant access. Choose the access rights in the Selected column and move them to the Available column, to revoke access.

  5. Select Save.

    See Also: Logging in to the Oracle Database Security Central Console

Controlling Access by Target or Group

Learn about controlling access to targets or target groups.

To control which users have access to a target or group:

  1. Log in to the Oracle Database Security Central console as a super auditor.

  2. Select Targets.

  3. Select Access Rights tab in the left navigation menu.

  4. Select the name of the target or target group for which you want to redefine access rights.

    The Modify Access dialog for the specific target or group appears. It lists the user access rights to the target or group. Super auditors have access by default.

  5. In the Modify Access dialog, select the users for which you want to grant or revoke access to this target or group.

    1. Select the users for which you want to grant or revoke access to the targets or groups. You can also search for the users in the field.

    2. Choose the access rights in the Available column and move them to the Selected column, to grant access. Choose the access rights in the Selected column and move them to the Available column, to revoke access.

  6. Select Save.

    See Also: Logging in to the Oracle Database Security Central Console

Changing a User Account Type

Learn how to change auditor user account type.

You can change an auditor account type between Readonly Auditor, Auditor, and Super Auditor. If a user’s account type is changed from Auditor or Readonly Auditor to Super Auditor, that user will have access to all targets and target groups. A user can only be assigned one auditor account type at a time.

To change a user account type in Oracle Database Security Central:

  1. Log in to the Oracle Database Security Central console as a super auditor.

  2. Select Settings.

    The Manage Auditors page appears by default, and displays existing users and the targets or groups to which they have access.

  3. Select the name of the user account you want to change.

  4. In the Modify Auditor dialog, against the Type field, select on the edit icon.

  5. In the Type drop-down list, select the new auditor type.

  6. If you changed the type from Super Auditor to Auditor or Readonly Auditor, grant or revoke access to any targets or groups as necessary for this user.

    1. Select the targets or groups to which you want to grant or revoke access. You can also search for the targets or groups in the field under Targets & Target Groups.

    2. Choose the targets and groups in the Available column and move them to the Selected column, to grant access. Choose the targets and groups in the Selected column and move them to the Available column, to revoke access.

  7. Select Save.

    See Also: Logging in to the Oracle Database Security Central Console

Changing the Auditor Password

Learn how to change the password of an auditor.

Auditors can change their own password. A Super Auditor can also change the password of other auditors. If a Super Auditor changes the password of another auditor, then the password automatically expires immediately after it is changed.

See Also: About Oracle DBSecCentral Auditor Accounts and Passwords

Changing Your Own Password

You can change your own password any time.

  1. Log in to the Oracle Database Security Central console as an auditor.

  2. In the upper right corner, to the right of your login name, select the menu icon.

  3. Select Change Password from this menu.

  4. In the Change Password window, enter the following fields:

    1. Current Password

    2. New Password

    3. Re-enter New Password

  5. Select Save.

Changing the Password of Another Auditor

Learn how to change the password of another auditor as a Super Auditor.

A Super Auditorcan change the passwords of other auditors. However, the password automatically expires immediately after it is changed by the Super Auditor. The auditor must follow the instructions in the topic Changing the Expired Password of an Auditor.

  1. Log in to the Audit Vault Server as Super Auditor.

  2. Select Settings. The Manage Auditors tab in left navigation menu is selected by default.

  3. Under Manage Auditors, select the name of the auditor whose password you want to change.

  4. In the Modify Auditor window, select Change Password.

  5. In the Change Password window, enter the following fields:

    1. New Password

    2. Re-enter New Password

  6. Select Save.

Changing the Expired Password of an Auditor

Your password might be expired if a Super Auditor changes your password, or if it passes the password expiry date. You need to follow these steps:

  1. Log in to AVCLI with your auditor user name.

  2. AVCLI prompts to enter the password. Enter the expired password.

    The following message is displayed:

    The password has expired. Enter the new password:

  3. Enter the new password of your choice. Follow the password requirements.

    The following message is displayed:

    Re-enter password:

  4. Re-enter the new password.

  5. If the following message is displayed, then you have successfully logged in to AVCLI with the new password, and your account is active again:

    Connected to:
            Oracle Audit Vault Server - Version : 20.x.0.0.0

Note: If your attempt to log in fails for 3 times or more, then your account gets locked. You need to unlock your account and retry the above mentioned steps.

See Also:

Deleting an Auditor Account

As a Super Auditor, you can delete any auditor account except the last Super Auditor.

  1. Log in to the Oracle Database Security Central console as a Super Auditor.

  2. Select Settings.

    The Manage Auditors page appears by default, and displays existing users and the targets or groups to which they have access.

  3. Select the users you want to delete, and then select Delete.

    See Also: Logging in to the Oracle Database Security Central Console