Oracle expiring passwords alert


The Expiring Passwords alert notifies you when its configured condition is met on Oracle instances so you can investigate and respond.

Screenshot pending: Mini DBA Oracle Expiring Passwords alert screenshot placeholder

Alert summary

  • Platform: Oracle
  • Alert category: General
  • Default enabled: false
  • Default evaluation frequency: Hour
  • Threshold label: Days until expiry
  • Unit: days

What Mini DBA checks

Mini DBA describes this alert as: User passwords expiring soon Password expiration can cause application outages Notify application owners to update passwords Mini DBA evaluates this alert once an hour so changes are detected promptly.

How this alert helps

This alert helps administrators notice security-sensitive events before they become routine background noise. Failed authentication, expiring passwords, or audit issues can indicate access problems, misconfiguration, or active probing.

When to enable it

Enable it on production, shared, regulated, and externally reachable environments. You can use lower severity in isolated development systems, but keeping the signal visible helps catch account and permission drift early.

Threshold guidance

Threshold meaning: Days until expiry. Major threshold: 3 days. Minor threshold: 7 days. Comparison direction: under. For an under-threshold alert, increasing a threshold makes that severity fire sooner; decreasing it waits until the value falls further. Set the minor threshold as an early-warning level and the major threshold at the lowest acceptable value for the service.

Remediation for an active alert

Review the affected principals, source hosts, and recent access changes. Rotate or unlock accounts only after confirming ownership, remove stale permissions, investigate repeated failures, and document any security exception with an expiry date.

Investigation workflow

  1. Confirm the alert is still active and note the first seen time, affected instance, and severity.
  2. Review the affected principal, source host, authentication path, recent permission change, and audit trail in Mini DBA before changing configuration or ending sessions.
  3. Compare the current value with the normal baseline for the same time of day or maintenance window.
  4. Record the cause, corrective action, and whether thresholds or routing should be adjusted after the incident.

Avoiding alert noise

If the alert creates repeated noise, review whether it is enabled on the correct instances, whether maintenance windows are configured, and whether the minor and major routes match the real business impact. Keep enough history to prove the new setting before changing it broadly.

Related pages