Just don`t give them the sysdba privilege.
You can also set remote_login_passwordfile=exclusive
and use a password file (use orapwd for creating a password file) ... at least in 9i.


F.