| Lesson 2 | Configure Enterprise Manager Browser Access |
| Objective | Explain how to establish secure browser access to Enterprise Manager 24ai, discover supported Oracle AI Database 26ai targets, and verify monitoring. |
Oracle Enterprise Manager 24ai already provides a browser-based console. Setting it up means establishing the management infrastructure, securing access, and bringing supported database targets under management. Once configured, administrators can review database availability, inspect collected metrics, and perform operations permitted by their roles and credentials.
Enterprise Manager and Oracle AI Database have independent release numbering. An Oracle 26ai database installation does not automatically provide an Enterprise Manager 24ai deployment. This lesson explains the setup workflow; the installation and certification documentation supplies the requirements for your particular environment.
Important distinction: Enterprise Manager Database Express, or EM Express, is desupported in Oracle AI Database 26ai. The embedded EM Express setup procedure used with earlier database releases does not apply. Enterprise Manager Cloud Control supplies a separate management platform.
The browser is the administrator's entry point. Behind it, several components cooperate to collect information and carry out authorized work:
The browser connects to the console endpoint over HTTPS. It does not connect to the database listener to display the console. Also, monitoring a 26ai database does not imply that the repository must run 26ai. Repository certification and target certification are separate checks.
This diagram summarizes the component relationships. It is not a complete firewall specification or a requirement to place every component on a separate server.
First determine whether your organization already operates Enterprise Manager. If a suitable deployment exists, adding a supported database target usually avoids the need for another OMS and repository installation.
Before installation or discovery, confirm the following:
Consult Oracle's certification information and the documentation for the installed releases. A matching product family name alone does not establish compatibility. Record the selected versions and patches so another administrator can understand the deployment later.
For a new deployment, follow the Enterprise Manager 24ai installation guide to prepare the repository and install and configure OMS. Retain the installation's console endpoint and deployment details. For an existing deployment, obtain the approved endpoint and access procedure from its administrators.
Browser access is part of this platform. There is no separate conversion involving legacy console ZIP files, CGI programs, web aliases, or a browser Java plug-in. The administrator needs a supported browser and an approved network route to the console.
The console URL has this general form:
https://<oms-host>:<https-console-port>/em
Use the actual hostname and HTTPS console port assigned to your deployment. In an environment with a load balancer, the approved address may identify that service rather than an individual OMS host.
An authorized administrator can inspect OMS details by running the following command in an operating-system shell on the OMS host, using the OMS installation's emctl utility:
emctl status oms -details
The output includes service details and the console URL. The command may request the Enterprise Manager root password; enter it at the prompt. This is not a SQL*Plus command, and the database Oracle home is not necessarily the location of the correct utility.
Configure HTTPS with a trusted certificate matching the console hostname. Restrict access to approved administration networks or an approved remote-access service. Resolve certificate trust, expiry, or hostname errors before relying on the connection. Use the console URL, not an agent upload URL or a WebLogic administration endpoint.
Sign in with an Enterprise Manager administrator account. Console authorization and credentials for managed resources serve different purposes:
| Identity or credential | Purpose |
|---|---|
| Enterprise Manager administrator | Signs in to the console and receives roles and target privileges. |
| Database monitoring credential | Allows the agent and plug-in to collect database information. |
| Database administration credential | Authenticates database operations requiring the corresponding database privileges. |
| Host or job credential | Authenticates operating-system tasks or job execution where required. |
A named credential is a centrally managed credential that authorized administrators can use for applicable operations. It does not replace the need for appropriate privileges. Use individually assigned, appropriately privileged console accounts for routine work.
The Enterprise Manager SYSMAN administrator is not the target database's SYS account. Entering database SYS AS SYSDBA credentials is not the normal console sign-in procedure. Successful console login also does not authorize every operation on every target.
For the local-agent arrangement shown in the diagram, deploy or verify the Management Agent on the database host and the compatible Oracle Database plug-in where required. Confirm that the agent communicates with OMS before troubleshooting database discovery.
Use the supported discovery or manual-add workflow for your deployment:
For multitenant databases, verify the intended CDB and PDB targets. A PDB is not a separate database instance. Confirm its discovery and monitoring state rather than assuming that registering the host immediately makes every PDB ready for administration. Consult the documented workflow for your plug-in and target type.
A working login page proves that the console is reachable. It does not prove that the database is being monitored successfully. Check the agent's communication and recent uploads, the target's availability, metric collection times, and monitoring credential validation.
On the managed host, an authorized administrator can inspect the agent using the agent installation's utility:
emctl status agent
Keep this command separate from the OMS status command. They inspect different components and run from their respective installations. In the console, confirm that the intended administrator can see the correct targets and that their data is current. Check applicable licensing before using advanced management functions.
| Symptom | Check first |
|---|---|
| Console unreachable | Console URL, DNS, approved network route, HTTPS port, and OMS status. |
| Certificate warning | Trust chain, expiry, and hostname match. |
| Login rejected | Enterprise Manager identity, authentication configuration, and account status. |
| Database missing | Discovery and promotion completion, plus the administrator's target privileges. |
| Stale metrics or unavailable target | Agent communication, monitoring credentials, and connectivity to the database service. |
Investigate the reported condition before changing services. Restarting the database is not a general repair for console access. Likewise, opening unrestricted firewall access or changing database HTTPS settings does not resolve every OMS or agent problem.
Early Enterprise Manager releases used a Java console, but browser management predates Oracle Database 12c. Database Control in the 10g and 11g era was already web-based, as was Grid Control. Cloud Control continued the browser model. EM Express was a separate lightweight database tool, now desupported in 26ai.
With secure console access and verified target monitoring in place, you can prepare for scheduled work. The next lesson examines credentials and privileges for running jobs through Enterprise Manager.