Below are the equivalent ACF2 commands translated from the IBM AD Connect for Mainframe documentation.
Release : 16.0
RECKEY EZB ADD( PORTACCESS.SYSNAME.TCPIP.PROFILENAME UID(uid_for_stc) SERVICE(READ) ALLOW)
SYSNAME - represents the z/OS system name where the TCPIP started task is running.
TCPIP - represents the job name for the TCPIP started task on the z/OS system.
PROFILENAME - represents the unique profile name assigned to the port or port range for IBM AD Connect for Mainframe, as defined previously in the TCPIP profile data set. It follows the SAF keyword in that definition.
uid_for_stc - represents the ACF2 UID string for the IBM AD Connect for Mainframe started task logonid
Make sure the SERVAUTH class is made resident in INFODIR. If it is not, then issue the following:
CHANGE INFODIR TYPES(R-RSER)