Running your Web User Interface server with security not active
If the Web User Interface server is running with the CICS® system initialization parameter SEC=NO, users of the Web User Interface must provide a user ID to identify 'sessions' in the COVC transaction. Users are not required to provide a password.
The user ID does not need to be defined to the external security manager. Access checking of access to views, and CICS resources are based on the DFLTUSER for the Web User Interface server CICS region. All Web User Interface users have access to the View Editor and all menus, view sets and help members.
If security is not active, messages produced by auditing system programming interface commands contain the default user ID of either the CMAS or the MAS. See Changes to CICS SPI.