You can manage common and local users and roles for a multitenant environment by using Oracle Enterprise Manager.
Parent topic: Managing User Authentication and Authorization
Oracle Enterprise Manager Cloud Control supports the management of multitenant environment security.
In a multitenant environment, you can use Oracle Enterprise Manager Cloud Control to create, manage, and monitor common users and roles for both the root and the associated pluggable databases (PDBs).
Enterprise Manager enables you to switch easily between the root and a designated PDB.
In a multitenant environment, you can log in to a CDB or a PDB, and switch from a PDB to a different PDB or to the root.
Different variations of the Enterprise Manager Database login page appear automatically based on the feature that you had requested while logging in.
To log into a multitenant environment as a multitenant container database (CDB) administrator (an Enterprise Manager user who has the CONNECT
privilege on the CDB target) to use a CDB-scoped feature:
In a multitenant environment, Oracle Enterprise Manager enables you to create, edit, and drop common and local users.
A common user is a user that exists in the root and can access PDBs in the CDB.
Related Topics
You can edit a common user account from the root.
You can drop a common user from the CDB root.
Related Topics
A local user is a user that exists only in a specific PDB and does not have access to any other PDBs in the multitenant environment.
You can edit a local user from the PDB in which the local user resides.
In a multitenant environment, you can use Oracle Enterprise Manager to create, edit, drop, and revoke common and local roles.
Common roles can be used to assign common privileges to common users.
You can edit a common role from the root.
Related Topics
You can drop a common role from the root.
Related Topics
You can revoke common privilege grants from the root.
A common role can be used to assign a local set of privileges to local users later.
You can edit a local role in the PDB in which the local role resides.
Related Topics
You can drop local role from the PDB in which the local role resides.
Related Topics