Architecture / Identity

Multi-Factor Authentication on IBM i

Native IBM i sign-on is password-only. MFA is the single highest-leverage control most shops are still missing, and it is not a native OS feature you can turn on by yourself.

Last verified

Why IBM i Needs Third-Party MFA

IBM i has no native multi-factor authentication for 5250 sign-on. The operating system's own sign-on screen accepts a user profile and password, full stop. MFA on IBM i is always a third-party addition, typically implemented through an exit-point program that intercepts sign-on requests, or a system value / QIBM registration exit that hands authentication to an external service before the sign-on completes.

Where MFA Actually Needs to Apply

The most common mistake in an IBM i MFA rollout is covering 5250 green-screen sign-on and stopping there. Users and service accounts also reach the system through FTP, ODBC, JDBC, Telnet, SSH, and Access Client Solutions. A network security or exit-point product that only guards the green-screen sign-on leaves every other access path on password-only authentication.

5250 Sign-OnInteractive green-screen and terminal emulator access
Network Exit PointsFTP, ODBC, JDBC, DDM, remote command
Remote AccessSSH, Telnet, Access Client Solutions
Service AccountsOften exempted, which is itself a risk to review

Authentication Methods to Look For

FIDO2/WebAuthn hardware keys and platform authenticators are now the strongest widely-supported option and are increasingly required by cyber-insurance underwriters. RADIUS integration lets IBM i MFA plug into an existing enterprise MFA provider (Duo, Okta, Microsoft Entra) rather than running a separate authentication silo. Push-based mobile approval and TOTP (time-based one-time password) apps remain common and are easier to roll out to less technical users, though they are weaker against phishing than FIDO2.

Implementation Requirements

Exit Point Registration

MFA products register on sign-on and network server exit points; confirm no conflicting exit programs are already registered before deployment.

Fallback and Break-Glass Access

Plan an emergency access path for when the MFA service itself is unreachable, tested before you need it, not during an outage.

Service Account Policy

Decide deliberately which service accounts are exempted from MFA and document why; silent exemptions are a common audit finding.

Rollout Sequencing

Pilot with IT and a small user group before enforcing broadly; a botched enforcement can lock out an entire shift.

MFA closes the authentication gap. It does not replace authority management: a compromised MFA-protected profile that still holds *ALLOBJ can do just as much damage as one without MFA. Pair MFA with authority management and privileged access controls, not as a substitute for them.

Vendors Covering This Control

Fortra (Powertech)

Fortra's Powertech line (formerly HelpSystems, formerly PowerTech Group) is the longest-running dedicated IBM i security vendor and still the largest install base by most industry surveys, including its own annual State of IBM i Security Study. Powertech Multi-Factor Authentication, Authority Broker, Exit Point Manager, and Compliance Monitor are each strong standalone products.

Strengths

  • Largest install base among dedicated IBM i security vendors, with the deepest bench of IBM i-specific security expertise
  • Powertech Authority Broker is a mature, well-regarded privileged access / elevated-authority management product
  • Exit Point Manager provides granular network access control across FTP, ODBC, DDM, and remote command exit points
  • Publishes the annual State of IBM i Security Study, a widely cited independent-feeling data source (though vendor-funded)

Limitations

  • Product line grew through acquisition (PowerTech, Bytware, Robot, Vityl) and integration between modules is less unified than Precisely's single suite
  • Some legacy product UIs (Robot Console-adjacent tooling) show their age relative to newer competitors
  • Full stack pricing across MFA, Authority Broker, Exit Point Manager, and Compliance Monitor adds up for smaller shops

Best fit: Shops that specifically need best-in-class privileged access management (Authority Broker) or exit-point network control, and are comfortable managing several point products rather than one suite.

Precisely (Assure Security)

Precisely's Assure Security suite is the broadest single-vendor IBM i security platform on the market, spanning multi-factor authentication, encryption, compliance monitoring, and access control in one licensing family. It is the platform we point mid-size and enterprise IBM i shops to first when they need one vendor covering the most ground.

Strengths

  • Widest single-suite coverage: MFA, encryption, exit point control, and compliance monitoring under one console
  • Strong native IBM i journal-based monitoring with real-time SIEM forwarding (Splunk, QRadar, Sentinel)
  • Assure Encryption supports field-level and full-database encryption without application changes in most cases
  • Established install base and long IBM i-specific engineering history (originated from Townsend Security and Syncsort lineage)

Limitations

  • Suite pricing and licensing complexity increases as modules are added; full-suite cost is not the cheapest entry point
  • MFA client coverage for legacy green-screen sessions requires exit-point configuration that takes real implementation time
  • Reporting UI is functional but less modern than some newer point-solution dashboards

Best fit: Mid-size to enterprise IBM i shops that want one vendor for MFA, encryption, and compliance monitoring rather than stitching together point products.

Raz-Lee Security (iSecurity)

Raz-Lee's iSecurity suite covers firewall/exit-point control, antivirus, auditing, encryption, and MFA in a modular product line that is popular with mid-market IBM i shops, particularly in Europe. iSecurity Firewall and iSecurity Audit are the most commonly deployed modules.

Strengths

  • iSecurity Firewall gives real-time, rule-based exit-point control with strong logging detail
  • Native IBM i antivirus scanning (iSecurity Anti-Virus) is a differentiator versus vendors that rely on IFS-only scanning
  • Modular licensing lets smaller shops buy only the modules they need rather than a full suite
  • Strong presence and support infrastructure in European IBM i markets

Limitations

  • US market share and analyst mindshare trail Fortra and Precisely
  • Documentation and UI conventions can feel dated compared to Precisely's newer interfaces
  • MFA module is a newer addition to the suite with a shorter track record than Fortra's or Precisely's MFA products

Best fit: Mid-market shops, especially in Europe, that want modular exit-point firewall and native antivirus scanning without committing to a full enterprise suite.