---
name: db2-saas-user_mgmt
title: Managing users
description: ''
last-updated: 2026-01-30
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/db2-saas?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

{:external: target="_blank" .external}
{:shortdesc: .shortdesc}
{:codeblock: .codeblock}
{:screen: .screen}
{:tip: .tip}
{:important: .important}
{:note: .note}
{:deprecated: .deprecated}
{:pre: .pre}

# Managing users
{: #user_mgmt}

Access to IBM&reg; Db2&reg; as a Service service instances for users in your account is controlled by [Identity and access management (IAM) on IBM Cloud](https://cloud.ibm.com/docs/Db2onCloud?topic=Db2onCloud-iam&format=markdown) and database access is provided by standard access controls provided by the database.

For more information about IAM, see [What is IBM Cloud Identity and Access Management?](https://cloud.ibm.com/docs/account?topic=account-iamoverview&format=markdown).

## User types

{: #um_user_types}

### Database users

{: #um_db_users}

These are the users that are used to access the database. Traditionally, these are the OS users in a typical Db2 deployment, although, in the cloud, a user registry is used. Db2 understands these users as native to the database. The database privileges for the users can be granted or revoked as can roles that are created by the user.

Database users are not granted any service-level functions. For example, a database administrator who has access to the data does not have the ability to change the configuration of the system outside of the database privileges that they were given.

#### User Naming Rules

The user ID must follow the [general naming rules](https://www.ibm.com/docs/en/db2/12.1.0?topic=servers-general-naming-rules). It can contain up to 20 characters consisting only of:

- Lowercase letters (`a–z`)
- Numbers (`0–9`)
- Dot (`.`)
- At sign (`@`)
- Underscore (`_`)
- Hyphen (`-`)

The user ID cannot begin with a number or an underscore.

### Resolving Locked or Invalid Password Errors

{: #um_locked_pw}

When a user attempts to connect with an invalid password or after exceeding the maximum login attempts, the following error may occur:

```
Caused by: java.sql.SQLInvalidAuthorizationSpecException:
[jcc][t4][2017][11253][4.35.11] Connection authorization failure occurred.
Reason: User ID revoked. ERRORCODE=-4214, SQLSTATE=28000
DSRA0010E: SQL State = 28000, Error Code = -4,214

```

#### How to Resolve

{: #um_resolve}

1. **Verify credentials**
   - Ensure the correct database user ID and password are being used.
   - Check for typos, expired passwords, or case sensitivity issues.

2. **Reset password (if invalid)**
   - Use the *Change password* option in the console or via JDBC client.
   - Follow password policy rules (minimum length, complexity, history restrictions).

3. **Unlock account (if locked)**
   - If the account is locked due to failed attempts, wait for the configured *Lock Duration* to expire.
   - If immediate access is required:
      - Paid plans: An administrator must manually unlock the user via user management commands.
      - Lite/Free plans: Since no administrator is available, users must open a support case to request unlock assistance.

4. **Check password policies**
   - Review the configured `max_attempts`, `lock_duration`, and `failure_interval` to understand why the lock occurred.

5. **Escalate if unresolved**
   - If the account remains inaccessible, contact your Db2 SaaS administrator to verify IAM mappings and database privileges.

### IAM users
{: #um_iam_users}

IAM is only integrated with high-level service access, which governs privileges and operations available in the IBM Db2 SaaS console and database. Access to the database by these IAM users is provided by allowing an IAM user or service ID access to a specific Db2 user, as mentioned earlier.

### Roles and access

{: #um_roles_access}

Users can use JDBC or any Db2 client to connect to their database. There are two ways that users can access the database:

- Use their database user name and password associated with their account
- Use the IAM token (or APIKey, which gets the token) that is mapped to the associated database user

IAM authentication is performed as the authentication mechanism. Permissions are not controlled by IAM. Permissions are controlled by database level privileges of the associated user.

#### Console access

{: #um_console_access}

Console access is controlled by IAM. An IAM user can be assigned access by the IAM interface to all Db2 service instances, all Db2 service instances in a resource group, or a specific service instance. Within these parameters, IAM users can be assigned platform and service-level access.


| Role                               | User mgmt              | SQL editor/tables              | Monitoring info | Settings (includes scale, backup, DR, etc.) | Info panels |
|------------------------------------|------------------------|--------------------------------|-----------------|---------------------------------------------|----------------|
| IAM - Platform - Viewer            | No                     | No (unless mapped to Db2 user) | Yes             | No  | Yes |
| IAM - Platform - Operator          | No                     | No (unless mapped to Db2 user) | Yes             | Yes | Yes |
| IAM - Platform - Editor            | No                     | No (unless mapped to Db2 user) | Yes             | Yes | Yes |
| IAM - Platform - Administrator     | Yes                    | No (unless mapped to Db2 user) | Yes             | Yes | Yes |
| Non-IAM, but authenticate with JDBC | Only "Change password" | Yes | No | No | Yes |
{: caption="Roles and console permissions" caption-side="top"}

### Service action mapping

{: #um_serv_act_map}

Service action access is also controlled by IAM Roles. An IAM user can be assigned access by the IAM interface to all Db2 service instances, all Db2 service instances in a resource group, or a specific service instance. Within these parameters, IAM users can be assigned or revoked access from specific service actions.

| Role                           | Manage-users | Scale | Clone | Restore | DR  |Settings | Backup | Monitor | View settings    |
|--------------------------------|--------------|-------|-------|---------|-----|---------|--------|---------|------------------|
| IAM - Platform - Viewer        | No           |  No   | No    | No      | No  | No      | No     |  Yes    | Yes              |
| IAM - Platform - Operator      | No           |  Yes  | No    | Yes     | Yes | Yes     | Yes    |  Yes    | Yes              |
| IAM - Platform - Editor        | No           |  Yes  | Yes   | Yes     | Yes | Yes     | Yes    |  Yes    | Yes              |
| IAM - Platform - Administrator | Yes          |  Yes  | Yes   | Yes     | Yes | Yes     | Yes    |  Yes    | Yes              |
{: caption="Roles and service actions" caption-side="top"}


For more information about user management, see [Database user management](https://www.ibm.com/docs/en/db2oc?topic=features-database-user-management){: external}