MQRC 2035 — not authorized
An MQI call was refused by security. Find which call failed, under which user ID, against which object.
What happened
An application issued an MQI call — usually MQCONN or MQOPEN — and got completion code 2 (MQCC_FAILED) with reason code 2035, MQRC_NOT_AUTHORIZED.
MQOPEN failed CompCode=2 Reason=2035 Queue: PAY.REQUEST QMgr: QM01 Job log may also show: ICH408I USER(PAYBAT1 ) ... QM01.PAY.REQUEST CL(MQQUEUE ) INSUFFICIENT ACCESS AUTHORITY
What it means
The queue manager asked its security manager whether this user ID may do this operation and was told no. On z/OS that is usually RACF, with profiles in MQ classes such as MQCONN (connecting), MQQUEUE (opening queues) and MQADMIN. For client connections, channel rules can also block the connection itself. Nothing was put or got.
Typical causes
- The user ID has no access, or too little (for example READ when the open needs UPDATE for MQPUT).
- The program runs under a different ID than expected — a batch functional ID, the CICS transaction user, or the channel's user ID.
- A new queue was defined without a matching security profile change.
- A RACF change was made but the queue manager's cached security was not refreshed.
- For clients, a channel authentication rule blocks the address or user, or credentials failed.
Symptoms
- Fails every time for one user ID and object; other users work.
- MQCONN 2035 means it cannot connect at all; MQOPEN 2035 means the connection worked but this queue is denied.
- Distinguish from 2085: there the object does not exist; here it exists but access is refused.
Where to look
- The application log for the failing call, queue name and queue manager.
- ICH408I messages in the job log or the queue manager's log, which show the user ID, profile and access.
- Queue manager and channel initiator logs for client connections.
- Channel definitions and
DISPLAY CHLAUTHoutput for client rules.
How to diagnose
- Find which call failed: MQCONN, MQOPEN or another.
- Note the exact object name and the open options used — they decide the access needed.
- Identify the user ID that was checked, using ICH408I if present.
- Ask the security team which profile protects the object and what access the ID has.
- For a client, check channel authentication rules and the channel's user ID settings.
- Check whether a recent security change was made but not refreshed.
How to fix
Request the correct access for the right user ID, ideally via a group. After RACF changes, the security team refreshes the RACF classes and the MQ administrator issues REFRESH SECURITY on the queue manager so the cached decision is dropped. If the program opens with more options than it needs, fix the program instead. Then rerun the job or restart the transaction.
How to prevent
- Include MQ security profiles in every change that adds queues or applications.
- Use generic profiles that match your queue naming standard.
- Open queues only with the options actually needed.
- Test under production-like user IDs.
Production considerations
Interview question
A batch job gets reason code 2035 on MQOPEN. What do you check?
Stuck on something else?
Ask the community or search the full course.