Oracle
Governing Oracle database and EBS access with SailPoint.
SailPoint aggregates Oracle database or EBS accounts and privileges and provisions grants and revokes.
- Oracle connector type: a database/application connector
- Onboarding: aggregate then correlate
- SailPoint can create accounts and grant or revoke roles and privileges in Oracle.
- Common issues covered in troubleshooting
Oracle databases and E-Business Suite carry significant enterprise access, from schema privileges to application responsibilities. Governing Oracle with SailPoint brings these accounts and grants under the same review, request and provisioning controls as everything else.
Connector type and how it connects
The Oracle integration is a database and application connector. It connects to Oracle Database or Oracle E-Business Suite to read accounts and privileges, typically via a privileged service account. As with every connector, the flow is the same: authenticate to Oracle, read accounts and entitlements during aggregation, and write changes during provisioning.
Onboarding the source
- 1. Configure the connection and credentials for Oracle.
- 2. Map the account schema, mapping Oracle accounts and their roles/privileges (or EBS responsibilities) to SailPoint accounts and entitlements.
- 3. Set the correlation logic so Oracle accounts attach to the right identities (typically on a stable key such as employee ID or email).
- 4. Run account aggregation and confirm accounts and entitlements load.
- 5. Verify correlation, watching for uncorrelated/orphan accounts.
Provisioning capabilities
SailPoint can create Oracle accounts and grant or revoke roles, privileges and responsibilities, driven by requests, roles and lifecycle events, with approvals and SoD applied before changes are made.
Entitlements and what to govern
Govern database roles and system/object privileges (for the database) or responsibilities (for EBS). Privileged grants deserve particular attention in certifications and SoD policy.
Troubleshooting
When Oracle aggregation or provisioning fails, work through the usual causes in order:
- Verify the Oracle service account credentials and connection string.
- Confirm the account has privileges to read and grant/revoke as required.
- Check network/listener access to the Oracle instance.
- Validate the privilege/responsibility schema mapping.
Common pitfalls
- Credential expiry (tokens/secrets) silently breaking the connector.
- Insufficient rights on the Oracle service account for the operations you need.
- Schema or correlation misconfiguration leaving accounts uncorrelated.