IBM i 7.6 Security Features and Enhancements

IBM i has long been recognized as a secure, fully integrated enterprise platform, relied upon to run mission-critical workloads on IBM Power Systems. With every new release, IBM continues to enhance its security capabilities to address emerging threats and evolving regulatory requirements. The transition from IBM i 7.5 to IBM i 7.6 demonstrates a significant evolution in security strategy, moving beyond foundational protection toward more sophisticated, identity-centric security controls.

Released in 2022, IBM i 7.5 concentrated on strengthening the platform’s security foundation through enhanced hardening measures and more secure default configurations. In contrast, IBM i 7.6, introduced in April 2025, delivers a more comprehensive and proactive security framework, placing greater emphasis on authentication, compliance, and minimizing the risk of modern cyberattacks. While native multi-factor authentication (MFA) is the headline enhancement, the release also includes a range of additional security improvements that collectively strengthen the platform’s overall security posture.

Security as a Core Design Principle in IBM i 7.6

Security is not just an enhancement in IBM i 7.6; it is a central theme. IBM has designed this release to help organizations align with modern cybersecurity frameworks, regulatory compliance requirements, and zero-trust concepts. The release focuses on strengthening identity verification, tightening access controls, and improving security monitoring capabilities.

This shift is particularly important as enterprise environments—like those running IBM i workloads—are increasingly targeted through credential compromise rather than traditional system vulnerabilities. IBM i 7.6 directly addresses this trend by fundamentally improving how users authenticate and how access is governed.

IBM i 7.6 enhances authentication controls beyond MFA by introducing additional parameters and configurations that allow administrators to enforce stricter identity validation. New options for authentication methods and TOTP configuration enable more granular control over how users authenticate

New function usage controls provide administrators with more precise ways to grant or restrict access to specific operations. For example, users can be given the ability to view certain system configurations without granting full administrative authority. This helps enforce the principle of least privilege, which is a fundamental component of modern security practices.

IBM i 7.6 further strengthens network security by providing enhanced controls that allow organizations to disable insecure connections and enforce the use of stronger encryption standards. In addition, outdated and less secure cryptographic algorithms have been deprecated or removed, helping ensure that data transmission aligns with current security best practices.

These enhancements are particularly significant because legacy protocols and weak encryption methods remain common targets for cyberattacks in enterprise environments. By minimizing dependence on obsolete technologies, IBM i 7.6 enables organizations to improve the security and resilience of their overall IT infrastructure.

ItemV7R5V7R6
Key EnhancementsBase OS 40, DB2 Database, IBM i license programs, Open-Source solutions supportedMulti-factor authentication (MFA) integration, TOTP support, offline MFA
SST/DSTMFA not supportedIndependent MFA supported here
Data-at-rest encryptionDoesn’t offer encryption for all storage poolsProvides native implementation of data-at-rest encryption for all system storage pools
QIBM_RUN_UNDER_USER_NO_AUTH functionThis function is not availableThis function is available
IOSYSCFG functionThis function is not availableThis function is available
CFGHOSTSVR commandThis command is not availableThis command is available
Exit Point QIBM_QSY_AUTHThis Exit point is not availableThis Exit point is available
IBM i ACSNeed minimum 1.1.9.8 to support MFA. Latest recommended.1.1.9.8 or previous works. Latest recommended

Fig.1 Major security features comparison between 7.5 and 7.6

How IBM i 7.6 Differs from IBM i 7.5

To understand the significance of IBM i 7.6, it is important to look at how it builds on the foundation established by IBM i 7.5. The earlier release was heavily focused on improving baseline security. It eliminated insecure defaults, introduced stronger password encryption based on modern cryptographic algorithms, and removed outdated system security levels.

IBM i 7.5 enhanced security by strengthening default system settings and expanding auditing capabilities, making the platform more secure from initial deployment. However, user authentication continued to rely largely on passwords, with advanced identity verification features not yet integrated into the core operating system.

IBM i 7.6 advances this security foundation by introducing modern identity and access management capabilities. The inclusion of native multi-factor authentication (MFA) marks a significant step forward in securing user access. Alongside MFA, the release delivers enhanced auditing, tighter access controls, and more secure default configurations, creating a platform that is better equipped to meet current security and compliance demands.

Put simply, IBM i 7.5 emphasized reducing security risks caused by configuration errors, whereas IBM i 7.6 shifts the focus toward preventing unauthorized access, strengthening identity verification, and providing greater insight into security-related activities

ItemV7R5V7R6
Release dateMay 2022April 2025
Processor SupportPower9, Power10, Power11Power11, Power10
KerberosDefault encryption types: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96Default encryption types: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96; removed: des-crc-sha1, des-cbcmac-sha1, des-cbc-crc
Disk Device TypeSupports D910  Does not support D910
JDKSupports JDK11Does not support JDK11
IBM Backup, Recovery and Media Services for i (BRMS)Supports both 5770BR1 and 5770BR2.Doesn’t support traditional 5770BR1 product. 5770BR2 is only supported product
IM VersionIM 1.9.3 or newer 1.9.x requiredIM 1.10 and higher not supported due to JDK 11 unavailability

Fig.2 Key enhancements comparison between 7.5 and 7.6

Conclusion

IBM i 7.6 represents a significant evolution in the platform’s security capabilities. By integrating multi-factor authentication, strengthening access controls, and enhancing auditing and compliance features, IBM has aligned the platform with modern enterprise security expectations.

For organizations running critical workloads on IBM i, upgrading to version 7.6 is not just about new features—it is about adopting a stronger, more resilient security model. The transition from password-based authentication to multi-factor verification alone delivers a substantial improvement in protection against credential-based attacks.

In today’s threat landscape, where identity is often the primary attack vector, the enhancements in IBM i 7.6 provide a clear path forward. They enable organizations to secure their environments more effectively, meet regulatory requirements, and confidently operate in an increasingly complex digital ecosystem.