Is there a way to restrict users from using the F13 "Remove All" in QSYSOPR message queue while remaining at a security level 20?
At QSECURITY level 20 you can't really restrict users from anything. If you examine each of your user's profiles you will see that they have *ALLOBJ security –- essentially security officer rights. So if allowed to break the answer into two parts, I would reply that yes, you can restrict users from deleting messages from the QSYSOPR message queue, but no, not if you're running at QSECURITY level 20 and they all have *ALLOBJ special authority.
MORE INFORMATION ON THIS TOPIC
The Best Web Links: tips, tutorials and more.
Search400's targeted search engine: Get relevant information on security.
Ask your systems management questions--or help out your peers by answering them--in our live discussion forums.
Check out this Search400.com Featured Topic: Top ten security tips
Dig Deeper on iSeries system and application security
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.