Fully-Automated Onboarding

Learn about the fully-automated onboarding option for OracleDB for Azure.

The fully-automated onboarding option for OracleDB for Azure is faster and more convenient than the guided account linking, but some organizations may have security policies that do not allow them to grant the required permissions to the Oracle Database Service enterprise application that runs in their Azure account.

Note

The automated onboarding process requires that the Azure user onboarding to OracleDB for Azure have at least one of the following admin roles: Application Administrator, Cloud Application Administrator, Privileged Role Administrator, or Global Administrator.

Using this process, an Azure user:

  1. Logs into the OracleDB for Azure sign-up page using their Azure credentials.
  2. Grants OracleDB for Azure the permissions it needs to complete the automated onboarding process.
  3. Selects one or more Azure subscriptions to link to OracleDB for Azure.
  4. Logs into an existing OCI account or creates a new OCI account.

Once you complete these onboarding steps, OracleDB for Azure automatically does the following:

  1. Creates an Oracle Database Service (ODS) enterprise application and custom roles in the Azure tenant's Azure Active Directory.
  2. Grants the ODS application the permissions it needs in each of the selected subscriptions.
  3. Creates the OracleDB for Azure groups in the Azure tenant's Azure Active Directory.
  4. Creates a Multicloud Link (MCL) configuration in the user's OCI tenancy.
  5. Updates the MCL with configuration settings for each of the linked subscriptions.
  6. Creates and configures the private link between Azure and OCI using Oracle Interconnect for Azure.
  7. Federates the Azure tenant's Azure Active Directory (AAD) to OCI IAM and configures it to only synchronize user accounts that are members of the OracleDB for Azure custom groups that OracleDB for Azure created in AAD.

    Important

    User records in Azure Active Directory must contain a last name and valid email address to work with OracleDB for Azure identity federation.
  8. Redirects the browser to the OracleDB for Azure Portal at http://multicloud.oracle.com/azure.

When the automated configuration finishes, OracleDB for Azure is fully operational. The Azure user that completed onboarding can login and use the OracleDB for Azure portal to deploy and provision databases for use in their Azure environment. Before other Azure users can log into OracleDB for Azure, an Azure administrator must either add Azure users or groups to the custom Azure Active Directory groups ODSA created during onboarding, or assign the OracleDB for Azure custom roles to Azure users or groups.

To onboard an Azure tenancy with OracleDB for Azure, the onboarding using must be assigned as an owner in Azure for each of the Azure subscriptions being linked to OracleDB for Azure. For help completing this step, see Assign a user as an administrator of an Azure subscription in the Azure documentation.

Instructions

The three sets of instructions provided below are for three slightly different sign up scenarios. You only need to complete one of the tasks listed below.