Key Takeaways
- PCI DSS v4.0 made TOTP-based MFA mandatory as of March 2025; Assure Security now enforces it across SSH, SFTP, and standard IBM i logons using Google Authenticator, Okta Verify, and Microsoft Authenticator.
- The latest Assure Security service pack introduces OIDC Device Flow authentication, closing the MFA gap for 5250 terminals, ODBC/JDBC connections, and batch jobs that traditional MFA couldn’t reach.
- Assure Security now integrates with Illumio Zero Trust Segmentation and IBM i OS v7.6’s native MFA exit point, so IBM i security fits into your broader enterprise security stack rather than operating apart from it.
IBM i has long been the backbone of mission-critical operations across banking, healthcare, manufacturing, and retail. And for years, a common assumption followed it: that the platform’s inherent security was enough. That assumption is increasingly hard to hold.
According to the of IBM i professionals now rank cybersecurity as their top concern. At the same time, IBM’s X-Force 2026 Threat Intelligence Index found that identity-based attacks surged 32% in the first half of 2025 alone, and vulnerability exploitation became the leading cause of incidents overall.
The stakes are real. The global average cost of a data breach hit a record $4.99 million in 2026 — a 12% increase over last year. If your organization is running IBM i, you’ve likely already made investments in security; now, the focus must be on ensuring those security tools are keeping pace.
At Precisely, that’s exactly the standard we hold Assure Security to. Over the past year, we’ve shipped meaningful improvements across authentication, enterprise integration, and platform resilience so that comprehensive IBM i security is easier to enforce and trust. Here’s a look at what we’ve delivered and where we’re headed.
A Year of Customer-Driven Innovation in Assure Security
Expanding MFA Across More of Your IBM i Environment
Multi-factor authentication (MFA) is no longer optional. PCI DSS v4.0 made TOTP-based MFA a mandatory requirement as of March 2025, and Microsoft’s research shows that MFA blocks more than 99% of account compromise attacks, even when credentials are already known. Despite this, applying MFA consistently across an IBM i environment has historically been a challenge, particularly across different access types.
We’ve been closing those gaps. In 2025, we extended Assure MFA to cover SSH and SFTP access — two connection types that were previously outside MFA’s reach, leaving file transfer sessions and command-line access unprotected.
We also delivered a dedicated MFA Users page in the Web UI, which means administrators can now create, update, and delete MFA-registered users without leaving the modern interface to work on the 5250 screen. These improvements were built directly from customer feedback gathered during our early access program.
Earlier this year, we added support for TOTP authenticator apps — including Google Authenticator, Okta Verify, and Microsoft Authenticator. This allows IBM i logins to be challenged by the same authenticator apps your team already uses everywhere else in the organization, extending enterprise-standard MFA practices to a platform that has often been left out of that equation.
Deeper Integration with Enterprise Security Tools
IBM i doesn’t operate in isolation, and neither should its security tooling. Two integrations delivered over the past year reflect that reality.
- Automation of the Illumio microsegmentation integration within Assure Security’s System Access Manager. Illumio’s Zero Trust Segmentation approach limits how far an attacker can move inside a network after gaining access — an increasingly critical control as ransomware and lateral movement attacks continue to climb. The automated integration reduces manual effort and makes the protection practical to deploy at scale.
- Compatibility with the new native MFA exit point instroduced with IBM i OS v7.6. Compatibility is built directly into Assure Security SAM, so customers running v7.6 can broaden MFA coverage across all applications — not just server logons — without needing separate tooling.
Stronger Foundations: Encryption, Compliance, and OS Readiness
Good security also means staying current. We completed full certification of Assure Security and Enforcive on IBM i OS v7.6, giving our customers confidence that their security tools work as intended on the latest platform — protecting against vulnerabilities that arise when security software lags behind OS upgrades.
We also addressed the CVE-2024-3596 RADIUS Protocol Spoofing Vulnerability, hardening Assure MFA’s use of RADIUS servers by adding the Message-Authenticator attribute required by the associated patch. If you’re a customer relying on RADIUS for authentication, this closes a real exposure without requiring you to re-architecture your setup.
On the encryption side, we retired the older CTR encryption mode and consolidated on the stronger CBC mode introduced in the 7.0.15 service pack. That means you can now be confident you’re on the current encryption standard, with no ambiguity about which mode is active.
Real-Time Audit Visibility Across IBM i LPARs
Compliance officers need to know what’s happening on their systems in near real time. We delivered new audit reporting capabilities — including reporting that identifies programs adopting elevated special authorities across all systems — so security teams have the automated, system-wide visibility that manual processes simply can’t provide. Where previously there was no built-in alerting for unauthorized privilege adoption or changes to approved program lists, you now have a clear, auditable picture across all LPARs.
Service Pack Spotlight: OIDC Device Flow Authentication
Our most recent service pack — Assure Security 7.0.29.00, released June 2026 — delivers a capability that addresses one of the more persistent authentication challenges in IBM i environments:
How do you apply modern MFA to devices and connections that weren’t designed for it?
OIDC (OpenID Connect) Device Flow authentication is the answer.
It enables strong authentication for 5250 terminals, ODBC/JDBC connections, and batch jobs — access types that lack a browser or keyboard input — by routing the authentication step to a secondary device, like a phone or computer. The user’s original session waits while they complete authentication on their phone; once verified, access is granted back to the originating device.
This matters because the authentication gap on headless and limited-input devices is one of the last remaining places where modern MFA simply hasn’t reached. The OAuth 2.0 Device Authorization Grant (RFC 8628) is a well-established standard for exactly this problem, and we’re bringing it to IBM i. For organizations that have worked hard to enforce MFA across their enterprise, this closes a meaningful remaining gap — and it does so without requiring changes to the existing device or connection type.
What’s Ahead: Deeper Integration with Your Security Ecosystem
As IBM i environments become more connected to the broader enterprise, one question keeps coming up: how do we make sure Assure Security fits into the security stack organizations already have, not alongside it?
That’s the central theme of what’s coming next. We’re working on deeper integration with enterprise security platforms, including support for LEEF2 for QRadar, which will enable better classification and correlation of IBM i security events within SIEM environments. We’re also calling for design partners on identity provider integration to help shape how IBM i MFA aligns with broader corporate authentication standards.
IBM i Security Has Changed. Has Your Security Tooling Kept Up?
The IBM i security landscape has shifted considerably. Regulators are raising the bar on already-strict requirements, attackers are getting faster, and the long-held assumption that IBM i is inherently protected — by obscurity or by design — is one that you can no longer rely on.
What we’ve built over the past year reflects a simple commitment: that Assure Security should grow alongside the threats your organization faces, not behind them. From TOTP (Time-based one-time password) compliance to device flow authentication and enterprise integrations, the work we’re doing is grounded in what you need to protect what matters most.
Your priorities shape what we build next. Tell us what’s on your IBM i security roadmap at [email protected].
FAQ: Common Questions About IBM i Security and Assure Security
Does Assure Security support PCI DSS v4.0 MFA requirements?
Yes. PCI DSS v4.0 made TOTP-based MFA mandatory as of March 2025. Assure MFA now covers SSH, SFTP, and standard IBM i logons using TOTP authenticator apps — including Google Authenticator, Okta Verify, and Microsoft Authenticator — meeting the requirement across the most common IBM i access types.
What is OIDC Device Flow authentication, and which IBM i connections does it protect?
OIDC Device Flow (RFC 8628) routes MFA to a secondary device — like a phone or computer — when the originating connection has no browser or keyboard. Assure Security uses it to enforce modern authentication on 5250 terminals, ODBC/JDBC connections, and batch jobs: access types that traditional MFA couldn’t reach.
How does Assure Security integrate with enterprise SIEM tools like IBM QRadar?
Upcoming support for LEEF2 format will allow IBM i security events to be ingested, classified, and correlated within QRadar and other SIEM environments — so IBM i is no longer a blind spot in enterprise security monitoring.
What is Illumio Zero Trust Segmentation, and how does Assure Security support it?
Illumio’s Zero Trust Segmentation limits how far an attacker can move inside a network after gaining access — a critical control as ransomware and lateral movement attacks increase. Assure Security’s automated Illumio integration within System Access Manager (SAM) reduces manual deployment effort, making this protection practical at scale for IBM i environments.
