IAM users need to be mapped to a database schema to be able to access the database. This applies to both ADB-S access methods – whether the user is using IAM database password or using an IAM token to access the database. The IAM user needs to either be mapped directly to a database schema (exclusive mapping) or needs to be a member in an IAM group that is mapped to a database schema (shared mapping). These mappings are done by the ADB-S DBA locally in the database.