Subscribe to Posts by Email

Subscriber Count

    696

Disclaimer

All information is offered in good faith and in the hope that it may be of use for educational purpose and for Database community purpose, but is not guaranteed to be correct, up to date or suitable for any particular purpose. db.geeksinsight.com accepts no liability in respect of this information or its use. This site is independent of and does not represent Oracle Corporation in any way. Oracle does not officially sponsor, approve, or endorse this site or its content and if notify any such I am happy to remove. Product and company names mentioned in this website may be the trademarks of their respective owners and published here for informational purpose only. This is my personal blog. The views expressed on these pages are mine and learnt from other blogs and bloggers and to enhance and support the DBA community and this web blog does not represent the thoughts, intentions, plans or strategies of my current employer nor the Oracle and its affiliates or any other companies. And this website does not offer or take profit for providing these content and this is purely non-profit and for educational purpose only. If you see any issues with Content and copy write issues, I am happy to remove if you notify me. Contact Geek DBA Team, via geeksinsights@gmail.com

Pages

Oracle 12.2: Lock Down Profiles

To restrict user operations at PDB levels and even more granular restriction, in 12.2 we can create Lock down profiles using "create lock down profile".

Here are some examples

CREATE LOCKDOWN PROFILE test;
ALTER LOCKDOWN PROFILE test DISABLE STATEMENT = ('ALTER SYSTEM');
ALTER LOCKDOWN PROFILE test ENABLE STATEMENT = ('ALTER SYSTEM') CLAUSE= ('flush shared_pool');
ALTER LOCKDOWN PROFILE test DISABLE FEATURE = ('NETWORK_ACCESS');
ALTER LOCKDOWN PROFILE test DISABLE OPTION = ('Partitioning');
ALTER LOCKDOWN PROFILE test DISABLE STATEMENT = ('ALTER SYSTEM') CLAUSE = ('SUSPEND', 'RESUME');

Then set at PDB level using static parameter

ALTER SESSION SET CONTAINER=PDB1;
ALTER SYSTEM SET PDB_LOCKDOWN = test SCOPE = SPFILE;
ALTER PLUGGABLE DATABASE PDB1 CLOSE;
ALTER PLUGGABLE DATABASE PDB1 OPEN;

Comments are closed.