Don't hold me to this, but if I recall correctly we have successfully done so on some of our customers machines. This shouldn't have any real effect for two reasons: - The profile is not supposed to be used to login interactively. - The default configuration has the profile without password, so as long as you have not defined password for it, it can't be used to login interactively anyway.
ZENDADMIN user profile only function is to own the ZENDSVR library. So there is no problem to remove sign-on option. You could also change ZENDADMIn user class to *SYSOPR and remove *SECADM special authority
For audit purposes our company would like to remove *ALLOBJ authority for this profile (ZENDADMIN). When we did, it seemed to have affected some of our apps that used the i5 Toolkit. I know we should be replacing the i5 Toolkit with the XML Toolkit but at the moment, we don't have the resources to do that. Is there a way to remove *ALLOBJ authority without having any ill affects?