To provision an Autonomous Database with a private endpoint, you must have the following resources already created: A VCN within the region that will contain your Autonomous Database with shared Exadata infrastructure. Cannot be changed after provisioning. A private subnet within your VCN configured with default DHCP options. Cannot be changed after provisioning. At least 1 network security group (NSG) within your VCN for the Autonomous Database. Can be changed or edited after provisioning. https://docs.oracle.com/en-us/iaas/Content/Database/Concepts/adbsprivateaccess.htm