Information
The DB2_LIMIT_FENCED_GROUP registry variable allows restricting the operating system privileges of the fenced mode process (db2fmp) to the privileges assigned to the DB2USERS group.
This variable only has effect if extended security is enabled (DB2_EXTSEC) and the Db2 Service Account is not LocalSystem.
This registry variable only applies to Db2 Servers running on Windows.
Rationale:
By default, the fenced mode process has access to both the DB2ADMNS and DB2USERS groups.
Solution
Run the following command to set the DB2_LIMIT_FENCED_GROUP registry variable to ON:
db2set DB2_LIMIT_FENCED_GROUP=ON
Default Value:
The default value of DB2_LIMIT_FENCED_GROUP is OFF.