ACF2 WARN mode for resource rules
search cancel

ACF2 WARN mode for resource rules

book

Article ID: 249486

calendar_today

Updated On:

Products

ACF2 - z/OS

Issue/Introduction

 Does ACF2 allow you to build a profile (for instance STGMGMT) in WARN mode so we can report on which users might need access to certain profiles?

Environment

Release : 16.0

Component : ACF2 for z/OS

Resolution

 ACF2 DOES allow for access rules (dataset) to be in warn mode when either WARN mode or RULE MODE is set
 by the Control(GSO) OPTS record.
the parameter is MODE. ..

MODE(ABORT|WARN|LOG|QUIET|RULE,norule,no$mode)

However this does not apply to resource rules.
Resource rules are always in abort mode.  

For resource rules you can allow and log accesses so that users will be allowed access AND
it will be logged to smf for review.
For example.

In a resource rule you can specify
$KEY(STGMGMT) TYPE(SAF) ROLESET
- USER(john) LOG
- ROLE(ABC) ALLOW 

anyone in role ABC will be allowed access and john will be alloWed access but logged to SMF