Preamble
Thinking about security in MySQL installation, you can consider a wide range of possible procedures/recommendations and their impact on the security of your MySQL server and related applications.
MySQL provides many tools/functions/plugins or components to protect your data, including some additional features such as Transparent Data Encryption (TDE), Audit, Data Masking & De-Identification, Firewall, Password Expiration Policy, Password Reuse Policy, Password Verification-Required Policy, Failed-Login Tracking and Temporary Account Locking, Dual Password Support, Connection-Control Plugins, etc.
Basic password policy practices teach us:
- Every user should have a password.
- User password should be changed periodically
Indeed, this is a good start!
What if MySQL makes your life easier by helping you create a user with a strong, secure password?
Well, it’s now possible in MySQL 8.0.
TL; DR
MySQL can generate randomly generated passwords for user accounts rather than requiring explicitly defined literal passwords from the administrator.
The database administrator can use CREATE USER, ALTER USER or SET PASSWORD to generate random passwords for user accounts.
Let us briefly review the use of MySQL 8.0.
MySQL SQL> SELECT VERSION();
+-----------+
| VERSION() |
+-----------+
| 8.0.19 |
+-----------+
Create user account
To create a new MySQL user account with a random password, use the CREATE USER operator with the offer IDENTIFIED BY RANDOM PASSWORD:
MySQL SQL>
CREATE USER aUser@localhost IDENTIFIED BY RANDOM PASSWORD;
+----------+-----------+----------------------+
| user | host | generated password |
+----------+-----------+----------------------+
| AndreyEx | localhost | M3BA1Po%as1Kse8Jt!aC |
+----------+-----------+----------------------+
Edit user account
To assign a new random password to a MySQL user account, use the ALTER USER operator with the IDENTIFIED BY RANDOM PASSWORD offer:
MySQL SQL>
ALTER USER aUser@localhost IDENTIFIED BY RANDOM PASSWORD;
+----------+-----------+----------------------+
| user | host | generated password |
+----------+-----------+----------------------+
| AndreyEx | localhost | SjAA*@(LA&fd43IOj>vS |
+----------+-----------+----------------------+
Assign Password
Rather of asking the administrator to supply precisely defined, literal passwords. MySQL can produce random passwords for user accounts.
MySQL SQL>
SET PASSWORD FOR aUser@localhost TO RANDOM;
+----------+-----------+----------------------+
| user | host | generated password |
+----------+-----------+----------------------+
| AndreyEx | localhost | 7kaJY^%x1<b8kT&84Du, |
+----------+-----------+----------------------+
Note that by default generated random passwords are 20 characters long.
This length is controlled by the system variable generate_random_password_length, which has a range from 5 to 255.
Create users with a random password in MySQL
About Enteros
Enteros offers a patented database performance management SaaS platform. It proactively identifies root causes of complex business-impacting database scalability and performance issues across a growing number of clouds, RDBMS, NoSQL, and machine learning database platforms.
The views expressed on this blog are those of the author and do not necessarily reflect the opinions of Enteros Inc. This blog may contain links to the content of third-party sites. By providing such links, Enteros Inc. does not adopt, guarantee, approve, or endorse the information, views, or products available on such sites.
Are you interested in writing for Enteros’ Blog? Please send us a pitch!
RELATED POSTS
How Can Government Agencies Improve Database Performance for Citizen-Facing Digital Services?
- 15 September 2026
- Database Performance Management
Government agencies increasingly depend on digital platforms to deliver essential public services. Government database performance monitoring helps IT teams detect slow queries, resource bottlenecks, abnormal workloads, and infrastructure issues before they affect citizen-facing systems. With better database visibility, agencies can improve application responsiveness, reduce downtime, accelerate troubleshooting, and support more reliable digital services across complex … Continue reading “How Can Government Agencies Improve Database Performance for Citizen-Facing Digital Services?”
How Can Manufacturers Prevent Database Performance Issues Across Production and ERP Systems?
Modern manufacturers depend on databases to support ERP platforms, production planning, inventory management, supply chain operations, quality control, warehouse systems, procurement, and connected manufacturing applications. Manufacturing database performance monitoring helps IT teams identify slow queries, resource bottlenecks, abnormal workloads, and emerging database issues before they disrupt production. With better visibility, manufacturers can improve system reliability, … Continue reading “How Can Manufacturers Prevent Database Performance Issues Across Production and ERP Systems?”
How Can Financial Institutions Improve Database Reliability Across Hybrid Cloud Environments?
- 14 September 2026
- Database Performance Management
Financial institutions can improve hybrid-cloud database reliability by combining continuous observability, workload-aware monitoring, resilient architecture, capacity planning, and faster root-cause analysis across on-premises and cloud systems. Strong hybrid cloud database reliability depends on seeing performance, availability, replication, SQL, and resource risks in one place. Enteros supports this with deeper visibility that strengthens BFSI cloud database … Continue reading “How Can Financial Institutions Improve Database Reliability Across Hybrid Cloud Environments?”
What Database Metrics Should Banks Monitor for Real-Time Transaction Processing?
Banks should continuously track database metrics for banking, including transaction latency, throughput, CPU utilisation, memory pressure, disk I/O, query performance, locks, waits, connection usage, replication lag, and error rates. Effective database monitoring for banks helps teams detect performance degradation early, protect real-time transaction processing, maintain application reliability, optimise infrastructure resources, and respond faster to emerging … Continue reading “What Database Metrics Should Banks Monitor for Real-Time Transaction Processing?”