Create and Manage Registration Policies in Oracle Data Safe
Overview
You can create a registration policy in Oracle Data Safe to automatically register pluggable databases (PDBs) in an ExaDB-D deployment.
By default, automatic registration enables the following Oracle Data Safe features on the target databases:
- Security and user assessment
- Audit collection
- Audit setting
- Data discovery
Note
Note: You can enable the Data masking and SQL Firewall features after target registration is completed if needed. You cannot disable Security and user assessment. SQL Firewall management in Oracle Data Safe is only available for Oracle AI Database 26ai target databases.
For ExaDB-D, Oracle Data Safe automatically uses an existing private endpoint, or creates one if none exists.
Before creating a registration policy, be sure to complete the necessary preregistration tasks. See Preregistration Tasks.
Preregistration Tasks
The following table lists tasks that you need to complete before you enable automatic registration on a CDB.
| Task Number | Task | Links to Instructions |
|---|---|---|
| 1 | In Oracle Cloud Infrastructure Identity and Access Management (IAM), obtain permissions to automatically register your database. | Permissions to Automatically Register PDBs in Oracle Exadata Database Service on Dedicated Infrastructure. |
| 2 | (Optional) If you plan to create an Oracle Data Safe private endpoint before creating a registration policy in Oracle Data Safe, make sure that the private endpoint can connect to the CDB and PDB listener endpoints. You are responsible for configuring required network security groups, security lists, route tables, firewalls, and other network controls. Oracle Data Safe does not modify these customer network resources automatically. | Create an Oracle Data Safe Private Endpoint. |
Create a Registration Policy for a CDB in Oracle Data Safe
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
Select Create registration policy.
The Create registration policy panel opens.
-
Select the compartment that contains your Exadata VM cluster.
-
Select the name of your Exadata VM Cluster.
-
Select the name of your container database.
-
Enter a name for your registration policy.
-
(Optional) Enter a description for your registration policy.
-
Select Oracle Data Safe features to be allowed with the PDBs.
By default, Security and user assessment, Audit collection, Audit setting, and Data discovery are selected. Security and user assessment cannot be disabled.
-
For Connectivity, Oracle Data Safe automatically uses an existing private endpoint for ExaDB-D, or creates one if none exists.
-
(Optional) Add a tag.
-
Select Create.
Oracle Data Safe creates a registration policy for the CDB, begins discovering and registering eligible PDBs in the background, and enables the default features on the registered target databases.
Post Registration Tasks
The following table lists tasks that you need to complete after you enable automatic registration on a CDB.
| Task Number | Task | Link to Instructions |
|---|---|---|
| 1 | (Optional) Modify which features are granted on your registered target databases. | Edit Feature Grants in a Registration Policy Edit Feature Grants on a Registered Target Database |
| 2 | Make sure to allow ingress traffic to your target database from the Oracle Data Safe private endpoint. | (none) |
View Details for a Registration Policy
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy whose details you want to view.
-
On the Details tab, view metadata for the policy.
General information:
- OCID - OCID for the registration policy. You can select Copy to copy the OCID to the clipboard.
- Compartment - Name of the compartment where the registration policy is stored.
- Enablement level - Pluggable database or Container database level
- Container database - Name of the CDB. You can select View details to navigate to the target registration details for the CDB.
- Created - When the policy was created
- Updated - When the policy was last updated
Connectivity details:
- Type - Data Safe on-premises connector
- Name - Name of the on-premises connector or private endpoint. For a private endpoint, you can select View details to navigate to its configuration.
Feature grants: Each of the following is Granted or Not granted. Security and user assessment cannot be disabled.
- Security and user assessment (granted by default)
- Audit collection (granted by default)
- Audit setting (granted by default)
- Data discovery (granted by default)
- Data masking
- SQL Firewall
-
On the Tags tab, view the configured tags for the registration policy and add more as needed.
Edit Feature Grants in a Registration Policy
When you edit the feature grants in a registration policy, you can apply the changes to all existing and future target databases or only to future target databases.
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy whose feature grants you want to edit.
-
From the Actions menu, select Edit feature grants.
The Edit feature grants panel opens.
-
Select the dropdown list, and then select the check boxes for the features that you want to grant. Deselect the check boxes for the features that you want to disable.
-
(Optional) Turn on Apply these changes to existing registered targets.
- When On, the features are granted to existing and future registered target databases.
- When Off, the features are granted only to future registered target databases. Existing target databases are left untouched.
-
Select Edit feature grants.
Edit Feature Grants on a Target Database that is Associated with a Registration Policy
You can edit features applicable to the target databases that are registered via registration policy targets.
-
Under Data Safe - Database Security, select Target databases.
-
In the table, search for and select the PDB whose feature grants you want to edit.
The page for the PDB opens where you can review the existing feature grants.
-
From the Actions menu, select Edit feature grants.
The Edit feature grants panel opens.
-
Select the dropdown list, and then select the check boxes for the features that you want to grant. Deselect the check boxes for the features that you want to disable.
-
Select Edit feature grants to save the changes.
Edit Connection Details in a Registration Policy
Updating the registration policy connection applies the new connection configuration to eligible existing targets in the background and to newly registered targets. Existing targets might temporarily show an updating status while Oracle Data Safe validates the new connection.
Note
Note: Once a target database is associated with a registration policy, you cannot edit the target database’s connection details. You can, however, modify the Oracle Data Safe private endpoint. If a target database is no longer part of a registration policy, then you can edit its connection details.
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy whose connection details you want to edit.
-
From the Actions menu, select Edit connection.
-
Select Update.
Edit the Display name for a Registration Policy
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy whose display name you want to edit.
-
From the Actions menu, select Edit display name.
-
Enter a new display name, and then select Update.
Edit the Description for a Registration Policy
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy whose description you want to edit.
-
From the Actions menu, select Edit description.
-
Modify the description, and then select Update.
Move a Registration Policy
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy that you want to move.
-
Under the Actions menu, select Move resource.
The Move resource panel opens.
-
In the drop-down list, select a different compartment, and then select Move resource.
The registration policy is immediately moved to the compartment.
Delete a Registration Policy
Deleting a registration policy stops future automatic discovery and registration of PDBs for that policy. Existing target databases remain in Oracle Data Safe and can continue to be managed independently.
-
Under Data Safe - Database Security, expand Target databases, and then select Registration policies.
-
In the table, select the registration policy that you want to delete.
-
Under the Actions menu, select Delete. The Delete dialog box appears.
-
If you are sure that you want to delete your registration policy, select Delete.
The delete operation is asynchronous. Monitor the associated work request until the registration policy deletion is complete.
Migrate Target Databases to a New Registration Policy
A registration policy can bring existing, manually registered target databases under policy-based management. When the registration policy’s background discovery finds a PDB within its scope, Oracle Data Safe checks for an existing target database for that PDB. If a matching target database is found, Oracle Data Safe migrates the existing target database under the registration policy. The process is asynchronous and uses the PDB’s OCID to identify the target database.
The migration process is as follows:
-
Create the registration policy and configure its features and connection settings.
-
Wait for background discovery to process the PDB.
-
Check the registration policy’s target database details and any related events to confirm the migration outcome.
The following changes occur after migration:
-
Oracle Data Safe associates the existing target database with the registration policy and adds system tags to identify it as policy-managed and migrated.
-
The
DATASAFE$ADMINaccount becomes system-managed. -
Features from the existing target database and the registration policy are merged.
-
Updates to the username or credentials of a policy-managed target database are restricted.
-
A migration event
TARGET_ACTION_MIGRATED, is emitted when the target database is successfully associated with the registration policy.