Access control
The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.
Access controls determine whether access to a particular resource should be granted or denied. It only allows access to resources to those users permitted to use them.
- Anti-CSRF token validation time
The glide.security.csrf_previous.time_limit property specifies the time in seconds for a secure token to expire. - Apply domain separation on dot walked fields
The glide.sys.domain.include_domain_condition_on_join property controls whether join queries are given domain separated conditions or not in order to ensure they apply domain separation functionality for dot walked fields. - Block access for delegated developers
This configuration affects access for delegated developers that are updating user roles through script. When the configuration is compliant, the developer will not be able to update or insert records into the sys_user_has_role table without also having the user_admin role. - Block Expired Anti-CSRF Tokens
Block expired CSRF tokens to prevent cross-site request forgery attacks. - Check UI action conditions before execution
Use the glide.security.strict.actions property to enable checking of UI actions conditions in forms and lists before they execute. When you set this property to true, it adds an extra layer of validation on the table UI actions before they are executed. - Configure event management assignment group admin roles [New in Security Center 1.5]
Use the evt_mgmt.connector_assignment_group_admin_roles property to set which roles are authorized for admin access over the assignment group field in connector instances. - Configure Service Portal Widgets Allow List
Learn how to configure the glide.service_portal.widget.allow_list property securely so that the access control lists (ACLs) for the tables do not expose sensitive information. - Configure Service Portal Widgets Table Allow List
Learn how the glide.service_portal.widget.table_allow_list property enhances security by listing tables accessible to unauthenticated users through Service Portal widgets, dependent on additional checks and specific glide property settings. - Deny internal access to explicit external roles [Updated in Security Center 1.3 and 1.5]
Use system properties to determine whether external users can be assigned the snc_internal role. - Deny unauthorized access to request items
The glide.sc.req_for.roles.default property defines a default behavior for the retrieveAddress API. - Display recommendations for high risk UI pages
Decrease the likelihood of authorization errors, and unintended information disclosure by displaying recommendations for high risk UI pages. - Disable Adding Default Roles to Skill ACLs
Use system properties to control what roles are automatically added to generative AI skill ACLs. - Disable inbound emails for locked out users
Use the glide.pop3.process_locked_out property to control inbound email actions for locked out, active users. - Disable Voice Chat Guest Impersonation
Use a system property to ensure that voice interactions/conversations are recorded under the appropriate internal integration user. - Double check inbound transactions
Use the glide.security.strict.updates property to enable double-checking of security on inbound transactions during form submission. When you set this property to true, it adds an extra layer of table validation before a form renders in the browser. - Enable scoped admin application ACLs
The glide.security.scoped_administration.honor_global_acl determines whether an application administration app can inherit global access control list (ACL) rules. - Enable work order management query rules for service organizations
Use the sn_fsm.use_query_rules property to apply rules and filters to the Field Service Management tables. - Enable ACLs to Control Live Profile Details
Use the glide.live_profile.details property to designate whether a user should be able to view all detail fields, such as company name and phone numbers, in a live profile. - Enable ACLs for Encoded Query in Simple List Widget
Learn how to set the glide.service_portal.enable_acls_for_encoded_query_in_list property to the secure value to prevent users from bypassing access control list (ACL) evaluations on a query condition in the Simple List Widget. - Enable Guardian for External Agents
Use a system property to protect your Language Learning Models (LLMs) with Guardian. - Enable Anti-CSRF token [New in Security Center 1.3, updated in 1.5, and removed in 2.0]
Use the glide.security.use_csrf_token property to ensure the use of a secure token to identify and validates incoming requests, which in turn are used to prevent these attacks. - Enable contextual security plugin
Activate the Contextual Security Plugin (com.glide.role_management) plugin to enable contextual security, which secures a record/information using create, read, write, and delete functionality. - Enable Cross Scope Privilege Checks on Service Portal Form [New in Security Center 7.0]
Use a system property to enforce cross scope privilege checks on the Service Portal form widget and prevent unauthorized retrieval of forms and table data between scopes. - Enable policy based session access for mobile
Use the The Zero Trust- Policy Based Session Access plugin to control if users authenticating through a mobile app will have their roles reduced. - Enable Role Masking for Agents
Use a system property to enable the role masking feature. - Enable multiple (permission policy and boundary) checks to ensure that the Role is privileged in AWS/Bedrock
Use a system property to determine what checks are used to verify whether a role is allowed to perform a privileged operation. - Enable report view ACLs
Manage a check for report_view ACLs of published reports. - Enforce ACL on HR Lifecycle Events Data [New in Security Center 2.0]
Learn how to prevent unauthorized access to data in the Human Resources Lifecycle Events application by verifying that the glide.enforce_security_scope.sn_hr_le property is set to the secured value. - Enforce ACL on HR Core Data [New in Security Center 2.0]
Learn how to configure the glide.enforce_security_scope.sn_hr_core property so that the Human Resources Scoped App: Core (com.sn_hr_core) plugin does not expose sensitive data to access control lists (ACLs) from all other scopes. - Enforce ACL on HR Virtual Agent Data [New in Security Center 2.0]
Discover how to set the glide.enforce_security_scope.sn_hr_va property to a secure value, preventing data leakage from the Virtual Agent Conversations scoped application. - Enforce application specific ACLs only for application data
Avoid unauthorized or undesired access to application data by enforcing application-specific access control lists (ACLs) only for application data. - Enforce application scope restrictions [New in Security Center 1.3 and removed in 1.5]
Use the glide.record.legacy_cross_scope_access_policy_in_script property to control the permissions of scoped apps. - Enforce field-level ACLs on records created from the query string of the Filtered List view UI of a table
Use a system property to prevent list filters from affecting the initial values of created records. - Enforce Read Roles for Catalog Variable Search [New in Security Center 7.0]
Use system properties to ensure that only catalog variables with an empty read role are indexed for search. - Enforce security rules to sharing dashboards
Use the glide.cms.dashboards.sharing_with_secure_search property to control whether users can share dashboards. - Enforce scope security for public sector digital services [New in Security Center 1.3]
Use the glide.enforce_security_scope.sn_gsm property to control how the application data from the Public Sector Digital Services application is accessed. - Enforce scoped ACL access for information request playbooks [New in Security Center 1.3 and updated in 1.5]
Use the glide.enforce_security_scope.sn_gsm_info_req property to control access to playbook data for the Information Request playbooks feature. - Enforce strict elevate privilege
Use the glide.security.strict_elevate_privilege property to control whether roles marked as privileged must be manually elevated for the user to be granted the role's capabilities. - Enforce security scope license and permit playbook [New in Security Center 1.5 and updated in 2.0]
Use this property to determine if only the access control lists (ACLs) within the License and Permit plugin will be used in determining access to the scope, or if ACLs from all scopes will be considered. - Enforce Security Scope for Agent Workspace for HR Case Management [New in Security Center 1.5 and updated in 2.0]
Configure the Agent Workspace for HR Case Management plugin so that data in scope master tables can only be accessed by users with the correct permissions, enforcing the principle of least privilege. - Enforce Security Scope for Service Application Information [New in Security Center 2.0]
Use the glide.enforce_security_scope.sn_svc_appl property to ensure that the data in master scope tables is secured. - Enforce Scope Access Controls on New Tables
Use a system property to enforce cross-scope access checks for newly created tables. - Enforce field level ACLs in GlideRecordSandbox
Manage field level ACLs in GlideRecordSandbox on your instance. - Enforce GroupBy ACLs
Configure your instance to conduct ACL checks on groupby columns. - Ensure archive table ACLs are checked
The glide.security.enable_archive_table_acls property controls whether access control lists (ACLs) of the original table, the table the archive table was created from, are evaluated to false. - Ensure dashboards creation/deletion requires access check [New in Security Center 1.3 and updated in 2.0]
The glide.processors.check_access_before_process system property enables access control list (ACL) enforcement for creating or deleting dashboards when a user is logged in. - Exclude Sensitive Tables and Fields from Data Generation [New in Security Center 7.0]
Use system properties to exclude tables and fields from Data Generation, which is used to generate fake data sets based on existing data. Tables and fields that are added to these exclusion lists can't be used for Data Generation feature. - Prevent Users From Accepting Warning To Bypass CSRF Validation [Updated in Security Center 1.3 and 1.5]
Use the glide.security.csrf.strict.validation.mode property to enable CSRF token strict validation. If the CSRF token doesn't match, it prevents resubmission of the request. - Restrict allowed domains for cross-origin iframe communication
Use a system property to enable cross-origin communication between iframes. - Restrict delegated developers read access [Updated in Security Center 1.3]
If com.glide.dd_allow_global_access_tables does not contain the recommended value of wf_activity, wf_activity_definition, wf_workflow, wf_workflow_version, sp_portal, sp_widget, and sp_page, then those tables could be read by a delegated developer. This could provide the delegated developer read access to sensitive information. - Require AJAXGlideRecord ACL checking
Use the glide.script.secure.ajaxgliderecord property to perform access control rule (ACL) validation when server-side records, such as tables, are accessed using GlideAjax APIs within a client script. - Restrict write access on system fields to admin users [New in Security Center 7.0]
Use the glide.rest.table_api.admin_only_sys_fields system property to control write access the fields generated by the system. - Require Multi-Factor Authentication for AI Voice Agent
Use a system property to control whether Multi-Factor Authentication (MFA) is required for the AI voice agent authentication feature. - Require approval for agent-based Office 365 group membership changes [New in Security Center 7.0]
Enable the approval flow for adding or removing Office 365 group members through the Microsoft 365 group membership AI Agent using a system property. - Prevent impersonating user from viewing application data
Use system properties to prevent an impersonating user from viewing application data. - Enforce oauth state parameter validation
Configure the glide.oauth.state.parameter.required property to prevent your instance from cross-site request forgery (CSRF) attacks. - Enforce Strict User Image Upload
Use the glide.security.strict.user_image_upload property to enable Access Control for the upload/update of a profile picture when performed on a user record. - Restrict email domains for external user registration [Updated in Security Center 1.3, 1.5, and 2.0]
Use the sn_ext_usr_reg.allowed_email_domains property to list acceptable external email domains. - Enable High Security Plugin
When you activate the High Security plugin, it creates or updates hundreds of different configurations to control the level of security on your instance. These configurations mitigate many of the top OWASP attacks by enabling strict access control, input validation, and output encoding. - Honor Admin Override ACLs
The glide.security.admin.override.accessterm property controls admins to be unable to override ACL evaluation even where the override should be in effect. - Prevent inactive users from logging in
Configure this property to control if inactive users can authenticate on your instance. - Prevent Unauthenticated Access to Virtual Agent Embedded Web Client
Learn how to configure the sn_va_web_client_app_embed table to block unauthenticated users from accessing embedded web clients. - Restrict JSONP Requests to Trusted URLs [Updated in Security Center 1.3]
Specify trusted URLs for the AngularJS $http service to allow or reject JSONP requests. - Prevent users from accepting warning to bypass CSRF validation
Reduce the risk of Cross-Site Request Forgery (CSRF) by preventing users from accepting warning to bypass CSRF validation. - Disable raw database query execution [Updated in Security Center 1.3 and removed in 2.0]
Control whether a user can perform raw SQL queries on the database. - Hide user comments on articles
Use the glide.knowman.show_user_feedback property to control whether feedback comments are visible. - Require authentication by default for client-callable script includes
By default, client-callable script includes that do not explicitly set visibility, are public. If needed, add the glide.script.ccsi.ispublic property to enable privacy control over all client-callable script includes accessed by public pages. - Enforce production instance behavior
Configure whether your instance should be handled like a production or non-production instance. - Restrict access to background script
Use a system property to set a role requirement for accessing the Script Background module. - Restrict access to emails with empty target table
Activate the glide.email.email_with_no_target_visible_to_all property to restrict user access to emails, unless they were the one who sent the email or have an admin role. - Restrict access to specific IP ranges plugin
Use the com.snc.ipauthenticator plugin to restrict access to specific IP ranges. Unless public access is intended for the instance, administrators should limit access to their assigned IP net blocks. - Restrict knowledge bases access
The glide.knowman.block_access_with_no_user_criteria property is used to control the read/write access of users on knowledge based articles. - Restrict permissions for CMDB model
Use the csm_cmdb_model.customer_visible_flag system property to limit customer access to data in the Product Models table as an additional access control to the CMDB model. - Restrict unauthenticated access to attachments
Restrict unauthenticated access to image attachments using a system property. - Restrict access to custom journal entries [Updated in Security Center 1.3 and removed in 2.0]
Use the glide.live_feed.custom_journal.acl_check_enabled property to respect ACL's on custom journal fields. - Restrict flow context read access
Use the com.snc.process_flow.reporting.require_flow_access property to enforce if an additional access check is required for a user to read a flow check. - Restrict Impersonation to Admin
The glide.sys.permissive.impersonate property can be used to prevent non-admin roles from impersonating other users. - Enable security jump start plugin (ACL Rules)
Activate the Security Jump Start (ACL Rules) (com.snc.system_security) plugin to create several important ACLs that validate the Access Controls on some of the key system tables within the ServiceNow AI Platform. - Use of secure insert multiple operation within import set API
Use the com.glide.import_set_api.insert_multiple_optimize property to control whether GlideRecordSecure or GlideRecord is used for the Insert Multiple operation within the Import Set API. - Enforce SOAP request strict security
Use the glide.soap.strict_security property to enforces web service security. - Required JMS connection factories
The mid.property.jms.command.allowed_factory_names property controls the Java Messaging Service (JMS) connection factories that the MID Server can use. - Restrict Global App Development by Role
Use the sn_g_app_creator.allow_global property to control which users can create applications in the global scope using the Guided Application Creator. - Review extraneous explicit role access control conditions [Removed in Security Center 1.5]
The Explicit Roles plugin is recommended to mandate that all users have either the snc_internal role to access internal resources, or the snc_external role to access external resources. - Specify URL allow list for cross-origin iframe communication
Use a system property to specify which domains you trust for cross-origin communication. - Set guest user for soap requests
Configure this property to control the level of access of unauthenticated SOAP requests. - Disable public access to favorites [Updated in Security Center 1.3 and 2.0]
Use the glide.ui.magellan.favorites.allow_public to specify whether unauthenticated users are allowed to see Favorites in the navigator. - Enable SNC access control plugin
Activate the SNC Access Control (com.snc.snc_access_control) plugin to control access to your instances by Customer Service and Support personnel. - Use Document Classification to limit publicly accessible documents [New in Security Center 7.0]
Control public access to permalinked documents using system properties. - Validate query ACLs on Glide DB functions [New in Security Center 7.0]
Control whether query ACLs are applied to Glide DB functions using system properties.
Parent Topic:Hardening settings