IBM i has long been recognized as a secure, fully integrated enterprise platform, relied upon to run mission-critical workloads on IBM Power Systems. With every new release, IBM continues to enhance its security capabilities to address emerging threats and evolving regulatory requirements. The transition from IBM i 7.5 to IBM i 7.6 demonstrates a significant evolution in security strategy, moving beyond foundational protection toward more sophisticated, identity-centric security controls.
Released in 2022, IBM i 7.5 concentrated on strengthening the platform’s security foundation through enhanced hardening measures and more secure default configurations. In contrast, IBM i 7.6, introduced in April 2025, delivers a more comprehensive and proactive security framework, placing greater emphasis on authentication, compliance, and minimizing the risk of modern cyberattacks. While native multi-factor authentication (MFA) is the headline enhancement, the release also includes a range of additional security improvements that collectively strengthen the platform’s overall security posture.
Security as a Core Design Principle in IBM i 7.6
Security is not just an enhancement in IBM i 7.6; it is a central theme. IBM has designed this release to help organizations align with modern cybersecurity frameworks, regulatory compliance requirements, and zero-trust concepts. The release focuses on strengthening identity verification, tightening access controls, and improving security monitoring capabilities.
This shift is particularly important as enterprise environments—like those running IBM i workloads—are increasingly targeted through credential compromise rather than traditional system vulnerabilities. IBM i 7.6 directly addresses this trend by fundamentally improving how users authenticate and how access is governed.
IBM i 7.6 enhances authentication controls beyond MFA by introducing additional parameters and configurations that allow administrators to enforce stricter identity validation. New options for authentication methods and TOTP configuration enable more granular control over how users authenticate
New function usage controls provide administrators with more precise ways to grant or restrict access to specific operations. For example, users can be given the ability to view certain system configurations without granting full administrative authority. This helps enforce the principle of least privilege, which is a fundamental component of modern security practices.
IBM i 7.6 further strengthens network security by providing enhanced controls that allow organizations to disable insecure connections and enforce the use of stronger encryption standards. In addition, outdated and less secure cryptographic algorithms have been deprecated or removed, helping ensure that data transmission aligns with current security best practices.
These enhancements are particularly significant because legacy protocols and weak encryption methods remain common targets for cyberattacks in enterprise environments. By minimizing dependence on obsolete technologies, IBM i 7.6 enables organizations to improve the security and resilience of their overall IT infrastructure.
| Item | V7R5 | V7R6 |
| Key Enhancements | Base OS 40, DB2 Database, IBM i license programs, Open-Source solutions supported | Multi-factor authentication (MFA) integration, TOTP support, offline MFA |
| SST/DST | MFA not supported | Independent MFA supported here |
| Data-at-rest encryption | Doesn’t offer encryption for all storage pools | Provides native implementation of data-at-rest encryption for all system storage pools |
| QIBM_RUN_UNDER_USER_NO_AUTH function | This function is not available | This function is available |
| IOSYSCFG function | This function is not available | This function is available |
| CFGHOSTSVR command | This command is not available | This command is available |
| Exit Point QIBM_QSY_AUTH | This Exit point is not available | This Exit point is available |
| IBM i ACS | Need minimum 1.1.9.8 to support MFA. Latest recommended. | 1.1.9.8 or previous works. Latest recommended |
Fig.1 Major security features comparison between 7.5 and 7.6
How IBM i 7.6 Differs from IBM i 7.5
To understand the significance of IBM i 7.6, it is important to look at how it builds on the foundation established by IBM i 7.5. The earlier release was heavily focused on improving baseline security. It eliminated insecure defaults, introduced stronger password encryption based on modern cryptographic algorithms, and removed outdated system security levels.
IBM i 7.5 enhanced security by strengthening default system settings and expanding auditing capabilities, making the platform more secure from initial deployment. However, user authentication continued to rely largely on passwords, with advanced identity verification features not yet integrated into the core operating system.
IBM i 7.6 advances this security foundation by introducing modern identity and access management capabilities. The inclusion of native multi-factor authentication (MFA) marks a significant step forward in securing user access. Alongside MFA, the release delivers enhanced auditing, tighter access controls, and more secure default configurations, creating a platform that is better equipped to meet current security and compliance demands.
Put simply, IBM i 7.5 emphasized reducing security risks caused by configuration errors, whereas IBM i 7.6 shifts the focus toward preventing unauthorized access, strengthening identity verification, and providing greater insight into security-related activities
| Item | V7R5 | V7R6 |
| Release date | May 2022 | April 2025 |
| Processor Support | Power9, Power10, Power11 | Power11, Power10 |
| Kerberos | Default encryption types: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96 | Default encryption types: aes256-cts-hmac-sha1-96, aes128-cts-hmac-sha1-96; removed: des-crc-sha1, des-cbcmac-sha1, des-cbc-crc |
| Disk Device Type | Supports D910 | Does not support D910 |
| JDK | Supports JDK11 | Does not support JDK11 |
| IBM Backup, Recovery and Media Services for i (BRMS) | Supports both 5770BR1 and 5770BR2. | Doesn’t support traditional 5770BR1 product. 5770BR2 is only supported product |
| IM Version | IM 1.9.3 or newer 1.9.x required | IM 1.10 and higher not supported due to JDK 11 unavailability |
Fig.2 Key enhancements comparison between 7.5 and 7.6
Conclusion
IBM i 7.6 represents a significant evolution in the platform’s security capabilities. By integrating multi-factor authentication, strengthening access controls, and enhancing auditing and compliance features, IBM has aligned the platform with modern enterprise security expectations.
For organizations running critical workloads on IBM i, upgrading to version 7.6 is not just about new features—it is about adopting a stronger, more resilient security model. The transition from password-based authentication to multi-factor verification alone delivers a substantial improvement in protection against credential-based attacks.
In today’s threat landscape, where identity is often the primary attack vector, the enhancements in IBM i 7.6 provide a clear path forward. They enable organizations to secure their environments more effectively, meet regulatory requirements, and confidently operate in an increasingly complex digital ecosystem.
