Is there a way to restrict a user with *ALLOBJ user profile
special authority from adding a job to the advanced job
scheduler? I changed the function authority to *EXCLUDE for
the user but the user can still add a job.
A couple of methods that were offered to restrict access to the command
are roadblocks that will hamper an unsophisticated user from using their
*ALLOBJ authority, but neither will prevent the user from adding
something to the job scheduler. A user with *ALLOBJ will always have
the means to undo security roadblocks like command exit programs and
group Special Authority limitations.
And yes users with *ALLOBJ can delete profiles - they just have to
employ a proxy user who has *ALLOBJ and *SECADM - which *ALLOBJ
authorizes them to do.
So the answer is, you have to either take *ALLOBJ away, or monitor and
report on the actions of the user who is doing it. The real issue is
not so much that someone has *ALLOBJ, it's that regulations and
compliance requires (more and more) that you be able to report on the
actions of *ALLOBJ users. The days of free flowing code slinging are
going away.
So find a way to remove *ALLOBJ, or to monitor it's use, or both.
PowerTech has a commercial application that does this, or you can write
an application yourself, but we're all going to have to rein in the
*ALLOBJ cowboys.
jte
--
John Earl, VP and Chief Technology Officer
PowerTech: 253-872-7788
Direct: 253-479-1408
Mobile: 206-669-3336
John.Earl@xxxxxxxxxxxxx
Email is an excellent way to communicate material that is not time
sensitive. If your communication is of a more urgent nature, please
call.
===========================
This email message and any attachments are intended only for the use of
the intended recipient named above and may contain information that is
privileged and confidential. If you are not the intended recipient, any
dissemination, distribution, or copying is strictly prohibited. If you
received this email message in error, please immediately notify the
sender by replying to this email message or by telephone and delete the
message from your email system. Thank you.
As an Amazon Associate we earn from qualifying purchases.