Sign-on system values: Restrict privileged users to specific device sessions

The Restrict privileged users to specific device sessions system value is also known as QLMTSECOFR. You can use this system value to specify whether users with all object (*ALLOBJ) and service (*SERVICE) special authority need explicit authority to specific workstations.

Quick reference
Location From IBM® Navigator for i, select Configuration and Service > System Values. Right-click on Signon and click Properties, then select theGeneral tab.
Special authority All object (*ALLOBJ) and security administrator (*SECADM).
Default value Deselected. Users are not restricted to specific device sessions.
Changes take effect Immediately.
Lockable Yes.
Lockable system value
(See Lock function of security-related system values for details.)

What can I do with this system value?

You can specify whether users with all object (*ALLOBJ) and service (*SERVICE) special authority need explicit authority to specific workstations. In the character-based interface, a value of 1 indicates that these users need explicit authority to specific workstations, and a value of 0 indicates that they do not need explicit authority.