Internet Features   «Prev  Next»

Lesson 2Configure Enterprise Manager Browser Access
ObjectiveExplain how to establish secure browser access to Enterprise Manager 24ai, discover supported Oracle AI Database 26ai targets, and verify monitoring.

Configure Enterprise Manager 24ai Browser Access for Oracle 26ai

Oracle Enterprise Manager 24ai already provides a browser-based console. Setting it up means establishing the management infrastructure, securing access, and bringing supported database targets under management. Once configured, administrators can review database availability, inspect collected metrics, and perform operations permitted by their roles and credentials.

Enterprise Manager and Oracle AI Database have independent release numbering. An Oracle 26ai database installation does not automatically provide an Enterprise Manager 24ai deployment. This lesson explains the setup workflow; the installation and certification documentation supplies the requirements for your particular environment.

Important distinction: Enterprise Manager Database Express, or EM Express, is desupported in Oracle AI Database 26ai. The embedded EM Express setup procedure used with earlier database releases does not apply. Enterprise Manager Cloud Control supplies a separate management platform.

Understand the Components

The browser is the administrator's entry point. Behind it, several components cooperate to collect information and carry out authorized work:

The browser connects to the console endpoint over HTTPS. It does not connect to the database listener to display the console. Also, monitoring a 26ai database does not imply that the repository must run 26ai. Repository certification and target certification are separate checks.

Enterprise Manager 24ai architecture showing an administrator browser connected by HTTPS to OMS, a management repository, and an agent with a database plug-in monitoring Oracle AI Database 26ai CDB and PDB targets.
Enterprise Manager 24ai provides browser-based management through OMS, a certified repository database, and managed-host agents. The setup workflow is to install or reuse the platform, secure access, discover supported database targets, and verify monitoring.

This diagram summarizes the component relationships. It is not a complete firewall specification or a requirement to place every component on a separate server.

1. Check Prerequisites and Compatibility

First determine whether your organization already operates Enterprise Manager. If a suitable deployment exists, adding a supported database target usually avoids the need for another OMS and repository installation.

Before installation or discovery, confirm the following:

Consult Oracle's certification information and the documentation for the installed releases. A matching product family name alone does not establish compatibility. Record the selected versions and patches so another administrator can understand the deployment later.

2. Install or Reuse the Management Platform

For a new deployment, follow the Enterprise Manager 24ai installation guide to prepare the repository and install and configure OMS. Retain the installation's console endpoint and deployment details. For an existing deployment, obtain the approved endpoint and access procedure from its administrators.

Browser access is part of this platform. There is no separate conversion involving legacy console ZIP files, CGI programs, web aliases, or a browser Java plug-in. The administrator needs a supported browser and an approved network route to the console.

3. Identify the Console URL and Secure Access

The console URL has this general form:

https://<oms-host>:<https-console-port>/em

Use the actual hostname and HTTPS console port assigned to your deployment. In an environment with a load balancer, the approved address may identify that service rather than an individual OMS host.

An authorized administrator can inspect OMS details by running the following command in an operating-system shell on the OMS host, using the OMS installation's emctl utility:

emctl status oms -details

The output includes service details and the console URL. The command may request the Enterprise Manager root password; enter it at the prompt. This is not a SQL*Plus command, and the database Oracle home is not necessarily the location of the correct utility.

Configure HTTPS with a trusted certificate matching the console hostname. Restrict access to approved administration networks or an approved remote-access service. Resolve certificate trust, expiry, or hostname errors before relying on the connection. Use the console URL, not an agent upload URL or a WebLogic administration endpoint.

4. Sign In with the Correct Identity

Sign in with an Enterprise Manager administrator account. Console authorization and credentials for managed resources serve different purposes:

Identities and credentials used in management
Identity or credentialPurpose
Enterprise Manager administratorSigns in to the console and receives roles and target privileges.
Database monitoring credentialAllows the agent and plug-in to collect database information.
Database administration credentialAuthenticates database operations requiring the corresponding database privileges.
Host or job credentialAuthenticates operating-system tasks or job execution where required.

A named credential is a centrally managed credential that authorized administrators can use for applicable operations. It does not replace the need for appropriate privileges. Use individually assigned, appropriately privileged console accounts for routine work.

The Enterprise Manager SYSMAN administrator is not the target database's SYS account. Entering database SYS AS SYSDBA credentials is not the normal console sign-in procedure. Successful console login also does not authorize every operation on every target.

5. Discover and Add Database Targets

For the local-agent arrangement shown in the diagram, deploy or verify the Management Agent on the database host and the compatible Oracle Database plug-in where required. Confirm that the agent communicates with OMS before troubleshooting database discovery.

Use the supported discovery or manual-add workflow for your deployment:

  1. Select the appropriate agent and discover the database, or supply its target properties manually.
  2. Review the database identity, connection properties, and discovered relationships.
  3. Provide monitoring credentials and configure the required secure database connection settings.
  4. Test the connection and correct credential or connectivity errors.
  5. Promote or add the target into management, then review its target home page.

For multitenant databases, verify the intended CDB and PDB targets. A PDB is not a separate database instance. Confirm its discovery and monitoring state rather than assuming that registering the host immediately makes every PDB ready for administration. Consult the documented workflow for your plug-in and target type.

6. Verify Monitoring Independently of Browser Access

A working login page proves that the console is reachable. It does not prove that the database is being monitored successfully. Check the agent's communication and recent uploads, the target's availability, metric collection times, and monitoring credential validation.

On the managed host, an authorized administrator can inspect the agent using the agent installation's utility:

emctl status agent

Keep this command separate from the OMS status command. They inspect different components and run from their respective installations. In the console, confirm that the intended administrator can see the correct targets and that their data is current. Check applicable licensing before using advanced management functions.

Troubleshoot the Failing Layer

Initial checks for common access and monitoring problems
SymptomCheck first
Console unreachableConsole URL, DNS, approved network route, HTTPS port, and OMS status.
Certificate warningTrust chain, expiry, and hostname match.
Login rejectedEnterprise Manager identity, authentication configuration, and account status.
Database missingDiscovery and promotion completion, plus the administrator's target privileges.
Stale metrics or unavailable targetAgent communication, monitoring credentials, and connectivity to the database service.

Investigate the reported condition before changing services. Restarting the database is not a general repair for console access. Likewise, opening unrestricted firewall access or changing database HTTPS settings does not resolve every OMS or agent problem.

Historical Context and the Next Step

Early Enterprise Manager releases used a Java console, but browser management predates Oracle Database 12c. Database Control in the 10g and 11g era was already web-based, as was Grid Control. Cloud Control continued the browser model. EM Express was a separate lightweight database tool, now desupported in 26ai.

With secure console access and verified target monitoring in place, you can prepare for scheduled work. The next lesson examines credentials and privileges for running jobs through Enterprise Manager.

Oracle Documentation


SEMrush Software 2 SEMrush Banner 2