IBM Support

Securing Objects from Users with *ALLOBJ Special Authority

Troubleshooting


Problem

Is it possible to secure objects from some users while these users require *ALLOBJ authority?

Resolving The Problem

Is it possible to secure objects from some users while these users require *ALLOBJ authority?

It is possible to secure objects from users and allow the users to have *ALLOBJ authority.

You can follow the steps:
1. Create a new group profile for the users in question.
2. Give the group profile *ALLOBJ authority.
3. Remove *ALLOBJ authority from the individual users.
4. Add the user to the Group Profile
5. To secure an object, give the individual users *EXCLUDE authority to the object.
The individual authority is checked first, and the user cannot access the object. For all other objects, the users have *ALLOBJ authority by using the group profile.
Warning: This is not a recommended practice. The user might find ways of getting authority to the excluded objects by Scheduling jobs with the Group Profile ID as the USER ID for the job.

[{"Type":"MASTER","Line of Business":{"code":"LOB57","label":"Power"},"Business Unit":{"code":"BU058","label":"IBM Infrastructure w\/TPS"},"Product":{"code":"SWG60","label":"IBM i"},"Platform":[{"code":"PF012","label":"IBM i"}],"Version":"6.1.0"}]

Historical Number

23035522

Document Information

Modified date:
27 August 2020

UID

nas8N1017404