Internet Features   «Prev  Next»

Lesson 3Prepare a Windows Account for Enterprise Manager Jobs
ObjectivePrepare a Windows execution account with the batch logon rights and resource permissions required for authorized Enterprise Manager host jobs.

Prepare a Windows Account for Enterprise Manager 24ai Jobs

Suppose you want Oracle Enterprise Manager 24ai to run a diagnostic command on a Windows host. You can sign in to the console and submit the job, but the command also needs a Windows identity under which to execute. Preparing that identity is a separate task from creating your Enterprise Manager administrator account.

A preferred user is not a special Windows account type. It is an ordinary account whose credentials can be selected for management operations. This lesson explains how to prepare the account for Enterprise Manager host jobs in a supported deployment managing Oracle AI Database 26ai environments.

Know Which Account Performs Each Task

For the host-job workflow described here, Oracle Management Service (OMS) coordinates the job and the Management Agent executes the host operation using the selected credentials. Prepare the Windows execution account for the host where the command will run. Creating an account only on the OMS server does not give it access to another server.

Separate identities involved in job execution
IdentityResponsibility
Enterprise Manager administratorSigns in to the console and holds authorization to access targets and submit jobs.
Management Agent service accountRuns the agent Windows service and satisfies its service requirements.
Windows job execution accountRuns the selected host command and accesses the resources it needs.
Database accountAuthenticates database operations with separately granted database privileges.

An existing configuration might use the same identity for more than one purpose, but these responsibilities remain distinct. Preparing a job account does not require changing the agent service identity, Oracle Home User, or database service account.

1. Confirm the Deployment and Job Requirements

Before creating an account, identify the execution host, job type, executables, and resources the operation needs. Record the Windows version and edition, domain membership, Enterprise Manager release update, Management Agent version, and relevant plug-ins.

If Windows Server 2025 is your intended platform, verify the exact combination in Oracle's current certification and release documentation. Oracle Database server, Oracle client, Management Agent, and OMS support are separate questions. A supported Windows client does not establish database server certification, and database certification does not establish agent certification.

For a job that invokes Oracle tools, also confirm the required tool versions and connectivity. This lesson assumes a supported deployment; it does not assert that every Oracle 26ai component can be installed on every Windows Server 2025 edition.

2. Select or Create the Windows Account

Use a dedicated account with a documented owner and permissions matched to the work. The following are illustrative names:

Use an explicitly qualified name to distinguish local and domain identities. A local account on one server is not automatically the same identity as an identically named account on another. Choose a domain account when the approved design requires domain resource access.

For a local account on a standalone or member server with the graphical management tools installed, an authorized administrator can:

  1. Open Computer Management.
  2. Navigate to Local Users and Groups > Users.
  3. Create the approved account and set its password using the organization's password-management process.
  4. Confirm that the account is enabled, unlocked, and ready for noninteractive use.

Use directory administration tools for domain accounts; this local-account procedure is not a domain-controller procedure. Resolve any requirement to change the password at the next logon before scheduling unattended work. Coordinate future rotation with the credential stored in Enterprise Manager.

Do not make the account an administrator or select a never-expiring password merely for convenience. A group managed service account also cannot simply be assumed to work in a username/password credential form; confirm support for the selected Oracle component and authentication method.

3. Grant the Batch Logon Right

The Windows right Log on as a batch job allows the account to perform a batch logon. Assign it on the execution host through the policy that governs that host. It does not itself grant permission to read scripts, write logs, administer services, or connect to Oracle.

Where local security policy is authoritative, use an authorized administrative session:

  1. Run secpol.msc to open Local Security Policy.
  2. Navigate to Local Policies > User Rights Assignment.
  3. Open Log on as a batch job.
  4. Add the intended account or approved group and verify the resolved name.
  5. Preserve other required entries and apply the change.
  6. Inspect Deny log on as a batch job, including assignments inherited through group membership.

A conflicting deny assignment blocks the logon even when an allow assignment exists. Adding the account to the allow list again does not resolve that conflict.

On a domain-managed host, the responsible administrator should configure the applicable Group Policy Object under Computer Configuration > Policies > Windows Settings > Security Settings > Local Policies > User Rights Assignment. Domain policy can overwrite local changes. Resolve policy conflicts with the policy owner rather than removing a broad deny rule without considering other accounts.

User-right changes apply to subsequent logons, including a new batch execution. A Windows reboot is not ordinarily required solely for this policy change. Agent installation or service reconfiguration can have separate restart requirements.

4. Grant Access to the Required Resources

Once batch logon is permitted, grant the resource permissions needed by the actual command:

For example, a diagnostic job might read an approved script from one directory and write a report to another. It need not have permission to modify that script or unrelated database files. Keep control of script modification separate from permission to execute it.

Use explicit paths and establish the required environment in the script. Unattended jobs should not depend on an interactive user's mapped drives, working directory, or profile settings. A command working under your personal administrator account does not prove it will work under the job account.

The agent service account may require additional documented Windows rights involving process creation or tokens. These are service prerequisites, not general permissions for every job account. Do not grant Act as part of the operating system, local administrator membership, or Oracle administrative group membership simply to make an ordinary diagnostic job succeed.

5. Understand Named and Preferred Credentials

Enterprise Manager can store the prepared identity as a named credential, allowing authorized users to reference it without embedding passwords in scripts. Access to the credential must be controlled separately from the Windows permissions it represents.

A preferred credential setting associates credentials with a target or target type in the applicable administrator context. It is not one universal Windows account for all OMS jobs. Depending on its type and configuration, a job can use preferred credentials or an explicitly selected credential.

The next lesson covers associating the account with Enterprise Manager host credentials. The handoff is straightforward: register the supported credential type, restrict who may use it, select it for the intended target or job, and validate. Check which credential the job actually references, especially after a password change.

6. Validate the Identity with a Harmless Job

After credential registration, submit a one-time diagnostic host job through the supported Windows command execution workflow. For a job configured to run a command body through the Windows command processor, use:

whoami
hostname

These lines are a command body, not a complete Enterprise Manager API request. The selected job type determines how to submit them. Review the job's output, status, and exit information in Job Activity.

Confirm that the reported identity matches the prepared account and that the hostname is the intended execution target. This establishes the execution context. Then validate required resource access with an appropriate benign operation. Do not use a database shutdown or patch operation as the initial credential test.

Troubleshoot Account and Permission Problems

Checks for Windows host-job failures
SymptomFirst checks
Credential validation failsQualified username, password, account lockout or expiry, host, and credential type.
Requested logon type is not grantedEffective batch-logon rights, deny assignments, group membership, and domain policy.
Command starts but access is deniedExecutable, script, directory, share, and applicable database permissions.
Wrong identity appearsExplicit job credential selection and preferred credential scope.
Interactive execution works but the job failsExecution identity, environment variables, working directory, mapped drives, and profile assumptions.
Failure follows password rotationAccount state and updates to the credential actually referenced by the job.
Agent cannot launch workAgent availability and documented service-account requirements.

Keep Scheduling and Notifications Distinct

Different mechanisms used for automated work
MechanismRelationship to this lesson
Enterprise Manager host jobAgent-mediated operating-system work using the selected execution credentials.
Oracle Scheduler, DBMS_SCHEDULERDatabase-managed scheduling. A PL/SQL job requires database privileges, not this Windows account merely because it is scheduled.
Scheduler external jobDatabase-scheduled external execution with its own credential and execution requirements.
Windows Task SchedulerA separate Windows scheduling service.
Enterprise Manager notificationsDelivery of notifications based on monitoring and incident rules, configured separately from host execution credentials.

For example, a tablespace utilization threshold can produce a monitored event and an email notification through configured rules and delivery settings. Creating a Windows batch account does not configure SMTP or enable those alerts. A corrective action that executes a host command is a separate operation requiring appropriate credentials.

You now have the account-preparation workflow: identify the execution host, provision the identity, configure effective batch-logon rights, and grant task-specific resource access. The next lesson associates that identity with Enterprise Manager host credentials and verifies its use.

Official References


SEMrush Software 3 SEMrush Banner 3