It is helpful to think of integrated Windows users as fitting into three basic types:
When the user profile attribute LCLPWDMGT(*NO) is defined for an i5/OS user, the i5/OS user profile password is set to *NONE. The i5/OS enrollment password is saved until Windows enrollment is successfully completed. After the i5/OS user is enrolled to Windows, the Windows user may change and manage their password in Windows without i5/OS overwriting their password. Using this method allows for a more secure environment because there are fewer passwords being managed. To read how to create a user of this type, see Changing the LCLPWDMGT user profile attribute.
User type | Function provided | User profile definition |
---|---|---|
Traditional |
|
LCLPWDMGT(*YES) and no EIM Windows source associations defined. |
Windows password-managed user |
|
LCLPWDMGT(*NO) |
Windows user with Enterprise Identity Mapping (EIM) associations auto configured | Automatic creation of Windows source associations makes it easier to set up and configure to use Kerberos enabled applications. | For example: EIMASSOC(*CHG *TARGET *ADD *CRTEIMID) |
Windows user with Enterprise Identity Mapping (EIM) associations manually configured | Allows the user to define EIM associations for enrolled i5/OS user profiles to be different user profiles in Windows. | Use iSeries Navigator to manually define EIM i5/OS target associations and Windows source associations. |