To move from running as an mqm user to a user that only has the authorities it needs and nothing more should probably done in a piece meal, step-by-step way. It should be noted that although these steps are designed to exhibit no change to the applications, the process should be run through on a test infrastructure before proceeding to production systems. Step 1: Create some non-mqm users with all authorities. In order to have applications running with only the authorities they need and nothing superfluous, you first need to be able to tell the applications apart. So our first step is to create some new user IDs that each application will use instead of using the mqm user ID. Initially we will create these users with privileges to everything so no change will be seen by the applications. These user IDs need to be created on the machine where the queue manager is running so that the component in the queue manager that checks authorities (the OAM on distributed pl