Hi Ashwini, I am not familiar with RAC server clustering, but isn't there a VIP for which you can define a device in PAM and have a single target account? You would then add all cluster members to a device group and define the VIP device as the credential source. If there is no VIP, you should be able to group the cluster members into a target group and define a job to update the accounts with the same password on the target group. Here a behavior of PAM that can be troublesome in other cases may help you. I am referring to the behavior that PAM always first tries to verify a new password before setting it. So if you have 5 devices getting their password updated, the first one processed will do the update, and the subsequent four would only do a verify and find that the new password is right already. This assumes that the password is updated on all cluster members in real time. The drawback with multiple target accounts referring to the same account on the cluster is that you should not configure password view policies that would trigger a password update on view or auto-connect, because that would update only one of the target accounts.