Database access should be limited to the applications or people that need it.
Steps
- Open the database management tool and select the intended database.
- Add a dedicated user or review the users already assigned to it.
- Grant the privileges required by the application. Use a separate limited account for read-only reporting where supported.
- When rotating a password, update the dependent application configuration immediately and test the site.
Good to know
Changing a database password can take the application offline until its configuration matches. Do not grant access to every database for convenience. Remote access may be restricted and should be arranged with Support rather than opened broadly.
Need help? Open a support ticket and include your domain and the step where you need assistance. Never include your password.