Secure your instance -- Platform security provides capabilities to secure the instance.
ServiceNow Vault -- ServiceNow Vault provides a single location to review and implement data security tools, including encryption, data discovery and classification, anonymization, zero trust access, and log export, to protect sensitive data across its entire lifecycle.
Exploring ServiceNow Vault -- Learn more about ServiceNow Vault and review the benefits it can provide for your data protection needs.
AI in ServiceNow Vault -- With the Now Assist for Vault application, you can automate many tasks in Vault with the help of AI. These tasks include securing custom applications to improve your security posture, checking role access for an encrypted column to monitor your instance’s encryption access posture, and others.
Vault Suite -- Vault Suite deploys the complete set of ServiceNow Vault capabilities on your instance automatically, eliminating manual plugin setup.
Install ServiceNow Vault -- Install the ServiceNow Vault application and assign the required roles.
Install Vault Suite -- Use Vault Suite to deploy ServiceNow Vault and its underlying plugins in a single step, without configuring each plugin separately.
Vault roles -- Learn and set up the roles necessary to use ServiceNow Vault.
Install plugins -- Learn how to review and install the necessary plugins for ServiceNow Vault.
Install Now Assist for Vault -- Install the ServiceNow Now Assist for Vault application from the ServiceNow Store to get Now Assist for Vault.
Use guided setup -- Use guided setup to configure an application with ServiceNow Vault.
Use agentic AI -- Use the Now Assist for Vault agentic workflows to complete tasks autonomously.
Access Observer configuration agentic workflow -- Use the Access Observer configuration agentic workflow to view, create, deactivate, and delete Access Observer settings for a particular field.
Summarize Access Observer logs agentic workflow -- Use the summarize Access Observer logs agentic workflow to review and summarize access logs for a specific field, identifying access sources, users, and their roles.
Use generative AI skills -- The Now Assist for Vault application includes the generative AI skills and features that enable you to streamline your administrative workload.
Schedule a Data Discovery job with Now Assist for Vault -- Use the schedule data discovery job skill to schedule one-time or recurring Data Discovery jobs with Now Assist. Data Discovery jobs can detect sensitive data such as PII or PHI provided as input to the Now LLM.
ServiceNow Vault console dashboard -- Use the ServiceNow Vault console dashboard to track and manage your ServiceNow Vault security tools.
Tools and metrics -- Learn about the tools and metrics ServiceNow Vault uses to protect and discover sensitive data.
Default policies and configurations -- ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly.
Now Assist for Vault -- With Now Assist for Vault, you can generate custom data patterns, check role access for an encrypted column, and schedule data discovery jobs. Now Assist for Vault can make it easier for you to perform common tasks without going to multiple systems.
Platform Security -- Platform security provides capabilities to secure the instance.
Security Center -- ServiceNow Security Center is an application that consists of a set of tools designed to help your organization maintain the security of your ServiceNow deployments. Using Security Center, you can improve security posture and strengthen compliance levels with a seamless user experience.
Security Center landing page -- Use the Security Center landing page to find the information and tools you need to secure your instance.
Security Tasks -- Use Security Tasks to monitor, prioritize, and assign all your security-related tasks in one place.
Edit Security Tasks -- Learn how to create, edit, delete, or export Security Tasks in Security Center
Export Security Tasks -- Learn how to export Security Tasks into files you can download and use in other software.
Security posture console -- Improve your ability to identify, respond to, and recover from security threats with comprehensive visibility and step-by-step instructions.
Security Best Practices -- Use Security Best Practices to implement privacy and security configuration tasks on your ServiceNow instance.
Complete a best practice -- Learn how to complete a security best practice on your ServiceNow instance.
View activity of a best practice -- Track the chronological and timestamped history related to a security best practice that you're completing on your ServiceNow instance, along with the user that initiated the activity.
View data of completed best practices -- See visual representations of the total amount of best practices completed, or segmented by maturity level.
Use a saved filter -- Apply filters to return more relevant results for your security best practices.
Best Practices -- Learn details about the Best Practices in the Security Posture Console.
Security posture dashboards -- Use the customizable single and multi-instance security posture dashboards to monitor your security KPIs. These dashboards consolidate the important information regarding the security of your instances in a single location and include a number of base system dashboard widgets.
Access Management -- Use the tools in the Access Management section verify that your data is only accessible to the users and processes that need it.
Security configuration console -- Use the security configuration page to get an overview of the security posture of your instance. View your hardening compliance score, discover graphical trends, analyze the top non-compliant hardening settings, and see the results of your security scans.
Security hardening -- View your hardening compliance score, compare it with previous scores, and change settings to improve your compliance score and security posture in the security hardening page.
All settings -- Review all of your instance hardening settings available from a single page.
Hardening settings details -- Analyze the details of a hardening setting by selecting its link within the Security Center app.
Filter hardening settings -- Simplify your hardening review process using filters. These filters can create a working list of hardening settings for review, which restored for later use and shared with other users.
Increase score -- Increase your hardening compliance score by ensuring that the hardening settings are compliant with the system's recommendations.
Hardening score comparison -- Gain visibility to the health of your hardening settings and use this data to improve the security posture of your instance.
Security scanner -- Scan your instance against a set of security checks to identify misconfiguration. The scanner tool simplifies the process of creating different suites of checks for different use cases so that you can analyze the results over time.
Scan findings -- A finding is a reference to a record that has violated a rule from a check on the instance. You can find the source record and additional information about the triggered rules, and how to resolve the finding.
Security scan comparison -- Compare two scans of the same security suite to gain visibility to the health of your hardening settings and improve the security posture of your instance.
Scan checks -- Use checks to detect anomalies within an instance, running against tables, records, or metadata.
Scan suites -- Review details on the scan suites available on your instance.
Access Controls Auditor checks -- Learn about the checks available in the default Access Controls Auditor Suites, what criteria they evaluate, and how they can be used to improve the security of your instance.
Security Center Scan Suites -- Use the Auditor suite to SecureCheck to detect misconfiguration that can impact the security posture of your instance.
Create a scan suite -- Create and schedule a custom suite so that you can analyze the security of your instance for your organization.
Clone the access controls auditor suite -- Clone and customize the default access controls auditor suite in your instance to create a new suite tailored to your organization's security practices.
View the Access Controls Auditor Suite -- View the checks available in the default Access Controls Auditor Suites to understand which checks are executed when this suite runs.
Scan results -- View data related to your scan results from a single view.
Customer Actions -- Use the Customer Actions tool to implement important security updates based on your instance and the configuration of plugins.
Implement Customer Actions -- Learn how to implement Customer Actions on your instance to increase its security posture.
View Customer Actions -- See details of all of the activity related to your Customer Actions.
Security monitoring console -- Supervise security notifications and metrics to stay informed about potential security risks on your instance.
Security Event Notifications -- View, manage, and analyze the default security event notification policies on your ServiceNow instance, as well as access the functionality to create custom policies.
Create custom policies -- Learn how to create custom security event notifications that are specific to your organization's needs. This enables you to monitor actions taken by users and groups on your instance and generate notifications for potential security risks.
Modify policies -- Learn how to modify the settings of your security event notification policies.
Configure policy preferences -- Discover how to customize security event notification policies in Security Center to align with your organization's specific needs.
Create custom email -- Learn how for creating a custom email for security event notifications by configuring new notifications, setting triggers, defining recipients, and crafting email content with dynamic event fields.
Security metrics -- Monitor over 50 different Security Metrics to identify potential security threats or insecure behaviors. Set thresholds for email notifications, visualize, and analyze the data in multiple ways. Export the data, or create dashboards with the metrics that are most important to your organization.
Customize the dashboard -- Discover the flexibility of the My security metrics dashboard, which can be customized with metrics from various sources like graphs and charts. Tailor the dashboard to suit your organization's specific requirements.
All Security Metrics -- Navigate to All Security Metrics to view a table with the data related to the Security Metrics of your instance.
Active Sessions -- View the trend line of the active users on the ServiceNow AI Platform.
Adaptive authentication Security Metrics -- Use authentication policies to evaluate authentication requests and deny or allow access to your instance based on the specified policy conditions.
Antivirus -- Displays the trend of when events occur on potentially infected files. See when they are discovered, placed into quarantine, restored, or deleted.
Authentication -- View trends for metrics related to authentication schemes, such as Multi-Factor Authentication(MFA) use, web service accounts, and biometric scanner usage.
Data Classification -- Access the Security Metrics for data classification on your ServiceNow instance.
Authentication metrics -- View metrics related to authentication on your instance from a dashboard.
Email -- Displays data related to spam emails that are being received externally.
Export -- Discover the data that is commonly exported, and which users do the exporting.
Integration Accounts -- View the trends about the integration accounts that are created on the ServiceNow AI Platform.
Privileged Identity -- Analyze data related to metrics for users with privileged identity.
Privileged Users -- View the trend line for the privileged users (active and inactive) and their activity on the ServiceNow AI Platform.
Session management -- View metrics related to user sessions and the frequency of lockouts of the sessions.
Users -- View the trend line for total users (active and inactive) and their activity on the ServiceNow AI Platform.
Security learning -- Access security learning materials from a single page.
ServiceNow Security Center announcements -- Enable security banner announcements and notifications to stay informed about urgent and critical security alerts using high visibility banners visible to administrators within the instance UI.
Granular roles for Security Center -- Use the new Security Center admin role to grant users security center administrative capability without using the admin role.
Instance Security Center -- Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.
Migrating to Security Center -- Learn the key differences when migrating from Instance Security Center (ISC) to ServiceNow Security Center (SSC).
Monitor security events -- Analyze the event metrics in your instance so that you can identify and prevent potential security events.
Configure the security event ribbon -- Configure the security event ribbon on the Instance Security Center homepage to include only those events that are relevant for tracking instance security in your operations. You can also change the order in which the security event tiles appear on the ribbon.
Set preferences for security event notifications -- Configure preferences for the types of notifications you want to receive for occurrences of specific security events. For each type, you designate whether to receive notifications by email, by push notification in Now Mobile, or in third party messaging applications such as Slack or Microsoft Teams.
Check the daily compliance score and configure security property settings -- Review the Daily Compliance Score metric and security configuration properties to see if your instance complies with the suggested security requirements. You can affect the daily compliance score by updating non-compliant security properties in the Hardening Compliance Configurations page.
Adjust instance security settings to increase compliance -- Using the Hardening Compliance Configuration page, harden and optimize non-compliant security properties that affect the daily compliance score of your instance. Its use ensures that your instance complies with the published security hardening standards, while fulfilling your company's security requirements.
How Daily Compliance score, trend, and graph data is refreshed -- Trend and graph data in the Instance Security Center is updated after the performance analytics job executes at 02:00 local time. It appears in the Daily Compliance Score tile, in the Event ribbon tiles, and in the KPI Details page detail.
PCI compliance score dashboard -- The PCI compliance score dashboard shows how your instance conforms to payment card industry (PCI) security standards. Use the dashboard to view your compliance score and modify your configuration to improve security.
PCI configuration controls score dashboard -- Use the PCI configuration controls score dashboard to review your PCI configuration and determine which security checks are non-compliant. You can change the configuration of the non-compliant security checks from the instance security center.
Scan for incorrect security definitions -- Run the Auditor to scan your instance and find incorrect security definitions. It provides findings you can correct to help improve the security posture of your instance.
Monitor instance metrics -- Monitor user, export, authentication, email, and antivirus metrics for your instance. For example, you can monitor your email security by checking metrics for spam, external emails, and inbound emails from untrusted and trusted domains for your instance. Analyze these metrics to look for anomalous security behaviors that are related to activities that take place in your instance.
User metrics -- Analyze user metrics to look for anomalous behaviors that are related to specific types of user activity in your instance.
Export metrics -- Analyze export metrics to see what data is most commonly exported and which users export the most data.
Export metrics settings -- Use the configuration options in the Settings tab to narrow down reporting results.
Authentication Metrics -- Analyze authentication metrics to see information related to authentication, such as infrequently used IP addresses, failed logins, and types of authentication schemes used by your users.
Adaptive authentication metrics -- Analyze adaptive authentication metrics to monitor and add insights on how adaptive authentication is being used on your instance.
Email metrics -- Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance.
Designate email domains as untrusted or trusted -- Designate specific email domains as untrusted or trusted so that you can monitor the metrics for incoming emails from these sources in your instance.
Antivirus metrics -- If the Antivirus Scanning plugin is activated, Antivirus Scanning runs in your instance to help protect it against virus infections from attachments.
MFA metrics dashboard -- The MFA metrics dashboard shows information on your instances multi-factor authentication configuration. Use the dashboard to ensure your MFA configuration meets your security standards.
Activate the ISC Virtual Agent interface -- If you have the admin role, you can activate the ISC Virtual Agent Conversations plugin (com.glide.isc_virtualagent). Activating this plugin installs the Virtual Agent and Natural Language Understanding (NLU content packs, providing Virtual Agent access from the Instance Security Center.
Hardening settings -- The ServiceNow Security Center (SSC) hardening settings content contains detailed descriptions and compliance values for the security-related system properties and plugins in the ServiceNow AI Platform. You can set these properties using the hardening settings app in the Security Center.
Baseline versions -- Explore how baseline versions for hardening settings align with family and store releases.
Baseline version 8.0 -- Some hardening settings have been removed with the release of Security Center baseline version 8.0.
Baseline version 7.0 -- Some hardening settings have been removed with the release of Security Center baseline version 7.0.
Baseline version 6.0 -- Some hardening settings have been removed with the release of Security Center baseline version 6.0.
Baseline version 5.0 -- Some hardening settings have been removed with the release of Security Center baseline version 5.0.
Baseline version 4.0 -- Some hardening settings have been removed with the release of Security Center baseline version 4.0.
Baseline version 2.0 -- Some hardening settings have been removed with the release of Security Center baseline version 2.0.
Access control -- The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.
Anti-CSRF token validation time -- The glide.security.csrf_previous.time_limit property specifies the time in seconds for a secure token to expire.
Apply domain separation on dot walked fields -- The glide.sys.domain.include_domain_condition_on_join property controls whether join queries are given domain separated conditions or not in order to ensure they apply domain separation functionality for dot walked fields.
Block access for delegated developers -- This configuration affects access for delegated developers that are updating user roles through script. When the configuration is compliant, the developer will not be able to update or insert records into the sys_user_has_role table without also having the user_admin role.
Check UI action conditions before execution -- Use the glide.security.strict.actions property to enable checking of UI actions conditions in forms and lists before they execute. When you set this property to true, it adds an extra layer of validation on the table UI actions before they are executed.
Configure Service Portal Widgets Allow List -- Learn how to configure the glide.service_portal.widget.allow_list property securely so that the access control lists (ACLs) for the tables do not expose sensitive information.
Configure Service Portal Widgets Table Allow List -- Learn how the glide.service_portal.widget.table_allow_list property enhances security by listing tables accessible to unauthenticated users through Service Portal widgets, dependent on additional checks and specific glide property settings.
Display recommendations for high risk UI pages -- Decrease the likelihood of authorization errors, and unintended information disclosure by displaying recommendations for high risk UI pages.
Disable Voice Chat Guest Impersonation -- Use a system property to ensure that voice interactions/conversations are recorded under the appropriate internal integration user.
Double check inbound transactions -- Use the glide.security.strict.updates property to enable double-checking of security on inbound transactions during form submission. When you set this property to true, it adds an extra layer of table validation before a form renders in the browser.
Enable scoped admin application ACLs -- The glide.security.scoped_administration.honor_global_acl determines whether an application administration app can inherit global access control list (ACL) rules.
Enable ACLs to Control Live Profile Details -- Use the glide.live_profile.details property to designate whether a user should be able to view all detail fields, such as company name and phone numbers, in a live profile.
Enable ACLs for Encoded Query in Simple List Widget -- Learn how to set the glide.service_portal.enable_acls_for_encoded_query_in_list property to the secure value to prevent users from bypassing access control list (ACL) evaluations on a query condition in the Simple List Widget.
Enable contextual security plugin -- Activate the Contextual Security Plugin (com.glide.role_management) plugin to enable contextual security, which secures a record/information using create, read, write, and delete functionality.
Enable policy based session access for mobile -- Use the The Zero Trust- Policy Based Session Access plugin to control if users authenticating through a mobile app will have their roles reduced.
Enforce ACL on HR Core Data [New in Security Center 2.0] -- Learn how to configure the glide.enforce_security_scope.sn_hr_core property so that the Human Resources Scoped App: Core (com.sn_hr_core) plugin does not expose sensitive data to access control lists (ACLs) from all other scopes.
Enforce strict elevate privilege -- Use the glide.security.strict_elevate_privilege property to control whether roles marked as privileged must be manually elevated for the user to be granted the role's capabilities.
Enforce GroupBy ACLs -- Configure your instance to conduct ACL checks on groupby columns.
Ensure archive table ACLs are checked -- The glide.security.enable_archive_table_acls property controls whether access control lists (ACLs) of the original table, the table the archive table was created from, are evaluated to false.
Restrict delegated developers read access [Updated in Security Center 1.3] -- If com.glide.dd_allow_global_access_tables does not contain the recommended value of wf_activity, wf_activity_definition, wf_workflow, wf_workflow_version, sp_portal, sp_widget, and sp_page, then those tables could be read by a delegated developer. This could provide the delegated developer read access to sensitive information.
Require AJAXGlideRecord ACL checking -- Use the glide.script.secure.ajaxgliderecord property to perform access control rule (ACL) validation when server-side records, such as tables, are accessed using GlideAjax APIs within a client script.
Enforce oauth state parameter validation -- Configure the glide.oauth.state.parameter.required property to prevent your instance from cross-site request forgery (CSRF) attacks.
Enforce Strict User Image Upload -- Use the glide.security.strict.user_image_upload property to enable Access Control for the upload/update of a profile picture when performed on a user record.
Enable High Security Plugin -- When you activate the High Security plugin, it creates or updates hundreds of different configurations to control the level of security on your instance. These configurations mitigate many of the top OWASP attacks by enabling strict access control, input validation, and output encoding.
Honor Admin Override ACLs -- The glide.security.admin.override.accessterm property controls admins to be unable to override ACL evaluation even where the override should be in effect.
Hide user comments on articles -- Use the glide.knowman.show_user_feedback property to control whether feedback comments are visible.
Require authentication by default for client-callable script includes -- By default, client-callable script includes that do not explicitly set visibility, are public. If needed, add the glide.script.ccsi.ispublic property to enable privacy control over all client-callable script includes accessed by public pages.
Restrict access to emails with empty target table -- Activate the glide.email.email_with_no_target_visible_to_all property to restrict user access to emails, unless they were the one who sent the email or have an admin role.
Restrict access to specific IP ranges plugin -- Use the com.snc.ipauthenticator plugin to restrict access to specific IP ranges. Unless public access is intended for the instance, administrators should limit access to their assigned IP net blocks.
Restrict knowledge bases access -- The glide.knowman.block_access_with_no_user_criteria property is used to control the read/write access of users on knowledge based articles.
Restrict permissions for CMDB model -- Use the csm_cmdb_model.customer_visible_flag system property to limit customer access to data in the Product Models table as an additional access control to the CMDB model.
Restrict flow context read access -- Use the com.snc.process_flow.reporting.require_flow_access property to enforce if an additional access check is required for a user to read a flow check.
Restrict Impersonation to Admin -- The glide.sys.permissive.impersonate property can be used to prevent non-admin roles from impersonating other users.
Enable security jump start plugin (ACL Rules) -- Activate the Security Jump Start (ACL Rules) (com.snc.system_security) plugin to create several important ACLs that validate the Access Controls on some of the key system tables within the ServiceNow AI Platform.
Use of secure insert multiple operation within import set API -- Use the com.glide.import_set_api.insert_multiple_optimize property to control whether GlideRecordSecure or GlideRecord is used for the Insert Multiple operation within the Import Set API.
Required JMS connection factories -- The mid.property.jms.command.allowed_factory_names property controls the Java Messaging Service (JMS) connection factories that the MID Server can use.
Restrict Global App Development by Role -- Use the sn_g_app_creator.allow_global property to control which users can create applications in the global scope using the Guided Application Creator.
Enable SNC access control plugin -- Activate the SNC Access Control (com.snc.snc_access_control) plugin to control access to your instances by Customer Service and Support personnel.
API and web service -- The API and Web Service category ensures that applications have appropriate authentication, authorization and session management, validate all input that traverses a trust boundary and include security controls for all API types.
Validate SOAP content type -- Use the glide.soap.require_content_type_xml property to enable validation of a content type as text/xml and protect against invalid SOAP requests.
Require authorization for PDF requests -- Use the glide.basicauth.required.pdf property to designate if incoming PDF requests should require basic authentication.
Require authorization for SOAP requests -- Use the glide.basicauth.required.soap property to designate if incoming SOAP requests should require basic authorization.
Require authorization for unload requests -- Use the glide.basicauth.required.unl (useUnloadFormat) property to designate if incoming unload requests should require basic authentication.
Require authorization for excel requests -- Use the glide.basicauth.required.excel property to designate if incoming Excel requests should require basic authentication.
Require authorization for import requests -- Use the glide.basicauth.required.importprocessor property to designate if incoming import requests should require basic authentication.
Require authorization for JSONv2 request -- Use the glide.basicauth.required.jsonv2 property to designate if incoming JSONv2 requests should require basic authorization.
Require authorization for WSDL request -- Use the glide.basicauth.required.wsdl property to designate if incoming WSDL (Web Services Description Language) requests should require basic authentication.
Require authorization for XML requests -- Use the glide.basicauth.required.xml property to designate if incoming XML requests should require basic authentication.
Require Authorization for XSD Requests -- Use the glide.basicauth.required.xsd property to designate if incoming XSD (XML Schema Definition) requests should require basic authentication.
Require authorization for script requests -- Use the glide.basicauth.required.scriptedprocessor property to designate if incoming script requests should require basic authentication.
Require authorization for SCHEMA requests -- Use the glide.basicauth.required.schema property to require basic authorization for all Inbound Table Schema Processor requests.
Require authorization for RSS requests -- Use the glide.basicauth.required.rss property to designate if incoming RSS requests should require basic authentication.
Require authorization for API requests -- Use the glide.basicauth.required.api property to enhance security for basic authorization for incoming REST requests.
Architecture, design, and threat modeling -- This broad control addresses high level design considerations and key elements to implement a secure application. This covers the tenants of availability, confidentiality processing integrity, non-repudiation and privacy. Additionally, elements of a secure software development lifecycle are included.
Disable legacy JQuery behavior -- The glide.jquery.legacy is used to prevent older prepatched JQuery versions from being used which will introduce unpatched vulnerabilities in the library.
Disable GlideRecord Scope Fencing Legacy Behavior -- The glide.record.legacy_cross_scope_access_policy_in_script property disables scope fencing allowing scoped apps to access global script interfaces. It was created as a patch to GlideRecord's cross scope access.
Disable unauthenticated published reports -- Deactivate this property to prevent the user from publishing or accessing reports. This property disables the published reports feature in reporting.
Disable public access to favorites -- Use the glide.ui.magellan.favorites.allow_public to specify whether unauthenticated users are allowed to see Favorites in the navigator.
Enable Anti-CSRF Token for Userperf -- Use a system property to ensure CSRF (Cross-Site Request Forgery) protection is enforced when setting user preferences.
Deny by default with empty ACLs [Updated in Security Center 1.3] -- Use the glide.sm.default_mode property to control the default behavior of security manager when it finds that existing Access Control List (ACL) rules are a part of wildcard table ACL rules.
Set Automatic Token Cleanup for Token Credentials -- Use the com.snc.platform.security.token.auth.cleanup property to ensure that expired API keys and HMAC secrets are deleted, thereby limiting the potential for token reuse.
Authentication -- The authentication category covers the main elements of modern authentication to confirm an entity and its claims are authentic and correct, resistant to impersonation and prevent interception of passwords.
Activate role based multi-factor authentication -- Use the glide.authenticate.multifactor property to enforce role-based multi-factor authentication (MFA) for all users assigned to specific roles.
Anti-CSRF token (instance security hardening) -- Use the glide.security.use_csrf_token property to ensure the use of a secure token to identify and validates incoming requests, which in turn are used to prevent these attacks.
Control Lockout Time for Invalid Password Reset Attempts -- The password_reset.request.max_attempt_window property controls the number of minutes a user must wait to reset or change their password after exceeding the maximum number of unsuccessful attempts that is set with the password_reset.request.max_attempt property.
Disable creating users from incoming emails -- Use the glide.user.trusted_domain property to specify the comma-separated list of trusted domains used in the creation of users from incoming emails.
Disable password-less authentication -- Use the glide.login.no_blank_password property to prevent users from logging into the NOW platform with blank passwords, or by leaving the Password field empty.
Enable CAPTCHA in password reset -- Use the password_reset.captcha.ignore property to enable or disable requiring a CAPTCHA challenge when a user resets their password.
Enable password reset policy checks -- Use the glide.enable.password_policy property to enable password policy checks whenever a user changes their password using the user interface.
Enforce device encryption and passcode requirements [New in Security Center 1.3] -- The glide.sg.device_encryption_enabled property enforces the Federal Information Processing Standard (FIPS 140-2) Encryption. Mobile device encryption and passcode ensure that an unauthorized user cannot access the content of a device even if the device is physically obtained.
Limit Invalid Password Reset Attempts -- The password_reset.request.max_attempt is used to control the maximum number of unsuccessful attempts that a user can reset or change their password before being locked out for a specified period of time.
Limit Allowed Number of Failed Login Attempts Before Lockout -- Two script actions are available that enable a site administrator to manage the number of times a user can provide an incorrect password before being locked out from the ServiceNow AI Platform. You can enable either of these script actions to manage failed login attempts.
Maximize failed login unlock timeout duration [Updated in Security Center 1.3] -- A script action is available that enables site administrators to manage the number of times a user can provide an incorrect password before being locked out from the ServiceNow AI Platform. You can enable this script action to manage failed login attempts.
Maximize reset password request unlock window duration -- The password_reset.request.unlock_window property controls the number of minutes a user must wait to start a reset request after the last successful unlock account action.
Maximize reset password SMS complexity -- The password_reset.sms.default_complexity property controls the minimum required SMS code verification size required during password reset.
Minimize reset password request success window duration -- The password_reset.request.success_window property controls the number of minutes a user must wait to reset or change their password again after successfully resetting the password. The user will be blocked to reset the password again for the specified duration.
Prohibit Use of KBA as Single Factor for AI Voice -- Use a system property to prevent Knowledge Based Authentication (KBA) from being the only factor of authentication required to authenticate to the platform for AI voice.
Require obfuscation of mobile app UI -- Configure the glide.sg.blur_ui_when_backgrounded property so that the UI of the app is blurred when the app is running in the background.
Business Logic -- This category looks at the logic and flow unique to each application with general secure principles. Specifically ensure that the intended sequence of business logic flow cannot by bypassed, that limits exist to detect and prevent automated attacks, and that protections against spoofing, tampering, information disclosure and elevation of privilege attacks exist.
Limit max comments per user per day -- Configure the sn_kb_social_qa.max_comments_per_user_daily property to restrict the number of QA comments per day.
Limit max subscriptions per user per day -- Configure the sn_kb_social_qa.max_subscriptions_per_user_daily property to limit the max number subscriptions a user can subscribe to in a day.
Minimize SMTP Recipient Quantity -- The glide.email.smtp.max_recipients specifies the maximum number of recipients the instance can list in the To: line for a single email notification.
Timeout Guest Sessions -- Use a system property to control the inactive session timeout for unauthenticated users.
Validate remote host -- Set the property to true to prevent bad actors from using internal port scanning in your network.
Communications -- This control ensures proper encryption using strong algorithms and ciphers. This includes ensuring the recommended version of TLS is used for client connectivity, use of strong cipher suites, use of trusted and signed certificates, ensuring connections are encrypted between components and logging of connection failures.
Disable outbound SSLv2/SSLv3 connections -- Use the glide.outbound.sslv3.disabled property to force the MID Server to use TLS when making outbound connections, such as REST and SOAP requests. Normally, outbound connections from an instance are forced to use TLS instead of SSL.
Enforce OCSP check on network error -- Learn how to configure the com.glide.communications.httpclient.ocsp_allow_network_error property to prevent bad actors from bypassing Online Certificate Status Protocol (OCSP) checks.
Verify certificate chain and hostname -- Configure the com.glide.communications.httpclient.verify_hostname property to prevent man-in-the-middle-attacks by ensuring that the certification verification process is executed.
Verify certificate revocation -- The com.glide.communications.httpclient.verify_revoked_certificate property checks certificate revocation during the Transport Layer Security (TLS) handshake to ensure that security checks are not bypassed.
Configuration -- The Configuration category ensures applications have a secure build environment and hardened third party library components. Specifically, ensuring a build and deploy pipeline is repeatable and includes automated testing and prevents known security issues from being deployed. This includes keeping dependencies up to date and free from known vulnerabilities.
Cache-Control HTTP Header Value [Updated in Security Center 1.3 and removed in 1.5] -- Use the glide.http.cache_control property to set the default cache-control value in the HTTP response headers that the ServiceNow AI Platform sends when requesting static content data for a page. Examples of static content include images, CSS, and JavaScript rendered from within, for a page.
Restrict performance monitoring access -- Use the glide.security.diag_txns_acl property to control stats.do, threads.do, thread_pool_stats, and replication.do access from an unauthenticated connection.
Enforce secure referrer policy -- Use the com.glide.security.referrerpolicy property to ensure that the Referrer-Policy HTTP header sends the appropriate level of data to each ServiceNow page to help prevent data leaks.
Ensure minimum private key size -- Use a system property to determine the minimum size of the private key used for Certificate Signing Request (CSR) generation with the Certificate Inventory Management application.
Data protection -- The data protection category addresses the elements of confidentiality, integrity and availability (CIA) of data.
Remove remember me -- Use the glide.ui.forgetme property to remove the Remember Me check box from the login page to prevent login information from being cached.
Require clearing pasteboard when backgrounding mobile application -- The glide.sg.clear_pasteboard_when_backgrounded property controls if text copied from ServiceNow mobile app is kept in the clipboard and pasteboard after the app is in background mode. If it is not set to the recommended value of true, then sensitive information may be disclosed to the Android or iOS clipboard where it can be exposed to other applications on the device.
Restrict HR case updates from personal emails -- Use the sn_hr_core.restrict_guest_email property to control whether a user can respond back to a HR case with their personal email.
Restrict oauth parameters to POST body [New in Security Center 1.3] -- Use the glide.oauth.allow.parameters.in.post.body.only property to control the inbound OAuth authentication's acceptance of access tokens. Access tokens are sensitive and should only be accepted when located within a POST request body.
Error handling and logging -- The error handling and logging category addresses the quality and verbosity of logged information exposed to stakeholders.
Enable MID audit log -- The MID Server command audit log records details such as the command name, command hash, name of credential used, and execution status.
Enable protected tables plugin -- Use the com.glide.security.protected_table.enabled property to prevent higher privilege users from tampering with log tables.
File and resources -- The file and resources category ensures applications handle untrusted file data securely and store untrusted data from untrusted sources with limited permissions in an appropriate location.
Disallow infected file download -- Control whether users can download non-scanned attachments if the antivirus service is down or unreachable.
Enable email spam scoring and filtering -- Install the Email Filter (com.glide.email_filter) plugin to install email filtering within the instance. This filtering identifies existing headers, which enables you to decide what to do with the email based on the associated header. Alternatively, set com.glide.email_filter to false.
Enable antivirus scan -- The com.glide.snap.enable_scan property activates the antivirus scan functionality.
Maximum allowed attachment size -- Configure the com.glide.attachment.max_size property to control the maximum size (in megabytes) permitted for an uploaded attachment.
Malicious code -- The Malicious Code category ensures that best efforts are made to confirm that your code is free of vulnerabilities and unwanted functionality.
Session management -- This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.
Minimize absolute session timeout duration -- Use the glide.ui.user_cookie.max_life_span_in_days property to set a maximum life span for user cookies created when users log in with the Remember Me checkbox selected. When the cookie expires, users who have selected the Remember Me checkbox are forced to reauthenticate into the instance.
Enable UserCookie version 3.1 -- Manage the version of UserCookie that is enabled on your instance to secure the storage of the secret key in the source code.
Limit concurrent sessions across all nodes -- Use the glide.authenticate.limit.concurrent.sessions.across.all.nodes property with the Limit Concurrent Sessions plugin to manage the number of sessions tracked across all nodes.
Limit guest's active session life span -- Use the glide.guest.active.session.life_span property to control the duration of an active guest's HTTP sessions.
Limit integrations' active session life span -- The glide.integrations.active.session.life_span property enforces max lifespan on active guest HTTP sessions irrespective of inactive timeout. The configured value is in minutes. A value of zero will disable timing out the active sessions.
Limit policy based session access mobile refresh token interval -- Use the glide.authenticate.session_access.mobile.refresh_token_interval property to govern the length of time that must elapse before a mobile device user will be forced to re-authenticate.
Limit UI active session life span -- The glide.ui.active.session.life_span property enforces max lifespan on active authenticated HTTP sessions irrespective of inactive timeout.
Rotate HTTP session identifiers -- Use the glide.ui.rotate_sessions property to enable rotation of the HTTP session identifiers to reduce security vulnerabilities.
Minimize session window timeout duration -- Use the glide.ui.user_cookie.life_span_in_days property to set the expiration time period for the Remember Me cookie. The default value is 15 days and the maximum cap is at 30 days.
Stored cryptography -- This category focuses on the encryption of stored data. It encompasses several key aspects, such as employing established algorithms and cryptographic modules, ensuring the proper generation of pseudo-random values, implementing encryption based on data classification, and securely storing and isolating key material.
Validation, sanitization, and encoding -- Validation, sanitization, and encoding addresses input validation to prevent against vulnerabilities like Cross-Site Scripting (XSS), SQL injection and other attacks.
Enable HTML Sanitizer [Updated in Security Center 1.3] -- Use the glide.html.sanitize_all_fields property to enable the HTMLSanitizer script include, which sanitizes HTML input based on exclusion listed and inclusion listed attributes configured in a script.
Enforce HTML Sanitization -- Use the com.glide.security.check_unsanitized_html property to enforce sanitization behavior of translated_html fields on a global level for field assignments.
Disable AJAXEvaluate -- Use the glide.script.allow.ajaxevaluate to protect the system API from vulnerabilities of Client script execution through AJAX calls.
Disable Entity Expansion within the XMLDocument2 Streaming Parser -- If customizations do not require entity expansion, use the glide.stax.allow_entity_resolution property to completely disable external entity expansion. The XML completes parsing but doesn't include any internal or external entities.
Disable JavaScript tags in embedded HTML -- Use the glide.ui.security.codetag.allow_script property to disable support for embedding HTML JavaScript code created using of the [code] tag.
Restrict downloadable MIME types -- The glide.ui.attachment.download_mime_types property will force the specified list of dangerous file types to be downloaded to the client and not viewed inline in the browser.
Enable Jelly JS Interpolation Protection -- Use the glide.ui.jelly.js_interpolation.protect property to ensure that any JavaScript about to be executed on a Jelly page is protected from injection with the help of Jelly interpolation.
Enforce relative links -- Use the glide.cms.catalog_uri_relative property to enforce relative links from the URI parameter on /ess/catalog.do.
Enforce URL allowlist check -- Use the glide.security.url.whitelist system property to add extra layer of validation to ensure whether any external URL introduced should be a part of inclusion listed URLs.
Escape scripts in scratchpad -- Learn how scratchpad factors into the security posture of your instance and how to manage it so that malicious scripts can't be executed on it.
Escape XML markup -- Use the glide.ui.escape_text property to force escape of XML values at the parser level before transmitting them to the client's browser.
Restrict access to GlideSystemUserSession scriptable API -- The client callable GlideSystemUserSessionSandbox scriptable API exposes GlideSystemUserSession's addErrorMessageNoSanitization and addInfoMessageNoSanitization methods to the JavaScript sandbox. This allows all users to call this method via script.
Packages call removal tool -- Activate and run the Packages Call Removal Tool (com.glide.script.packages_call_removal) plugin, and then consider whether each of the proposed changes should be completed or rejected.
Prevent Empty ACL Creation -- Set the glide.security.empty_acl.popup_window.enabled property to the secure value of true to block attempts to create, update, or save an invalid ACL. This setting will also provide a client-side model to configure a role or security attribute for the ACL.
Prevent Reuse of REST API Sessions in UI/Web -- Prevent REST API session cookies from bypassing Single Sign-On (SSO) and Multi-Factor Authentication (MFA) controls using a system property.
Restrict uploaded MIME types -- Use the glide.security.file.mime_type.validation property to activate MIME type checking for uploads. You can enable (set the property to true) or disable (set it to false) MIME type validation for file attachments.
Restrict XML external entities -- Configure system properties to ensure that your instance only processes XML from trusted sources to help prevent XML external entity (XXE) attacks.
Require XMLdoc2 entity validation with allowlist -- If customizations do not require entity expansion, use the glide.xmlutil.max_entity_expansion property to completely disable external entity expansion. The XML completes parsing but doesn't include any internal or external entities.
Sanitize All Translated HTML Fields -- Learn how to configure the glide.translated_html.sanitize_all_fields property to the secure value to ensure that all translated_html elements are sanitized with an HTML sanitizer.
Set safe content security policy for SVG files -- The com.glide.csp.self_script_src_svg property adds the script-src none directive to the HTTP Content-Security-Policy header when Scalable Vector Graphics (SVGs) are accessed through the Translation Memory Index (IIX) file extension.
Log Export Service (LES) -- Log Export Service (LES) lets you seamlessly export your instance system and application logs into your enterprise security analytic tools.
Explore -- The LES service provides a highly scalable and near real-time integration with your analytic tools that is easy to set up and maintain. If you're new to LES, read this overview section to learn what the tool can do.
Log sources -- Log Export Service (LES) can export log sources from some System Log Tables, the Audit Table, and Application Node Log Files.
Administer -- Use LES to create log source configuration and multi-topics for each source type.
Create source type and multi topics in the LES source table -- Consume logs for each source type by creating multiple topics per source type. You can now leverage the option of customized selection of specific topics for different log sources during the debugging process, without impacting the other log tables.
Update system property -- Update the glide.les.disable_logs_forwarding system property within the Log Export Service application to control log forwarding during migration or database reseeding operations.
Configure -- Use guided setup to step through the initial configuration of LES. Guided setup assists you with planning the roll-out of the product and performing the basic configuration to go live.
Kafka consumer -- Use guided setup to step through the initial configuration of LES for Kafka consumers.
Multi-consumer support using unique mid servers -- You can now precisely manage log consumption with a new multi-consumer system, enabling dedicated consumers and MID servers for each specific log stream.
Secure Hermes LES connection -- Secure your Kafka topics by generating a ServiceNow instance-signed certificate.
Use -- Use LES to review the log report dashboard.
Logs -- Logs module provides a variety of logs that you can use to troubleshoot and debug transactions and events that take place within the instance.
System logs -- The System Logs module provides a variety of logs that you can use to troubleshoot and debug transactions and events that take place within the instance.
System log -- View warnings and errors for instance processes, records, and non-critical events, such as memory usage on the server machine.
Transaction logs -- The transaction log records browser activity for an instance. To aid in debugging of system issues, you can filter transaction logs by application scope, limiting transactions that appear to only those transactions originating in specific scopes.
Client transaction timings -- The Client Transaction Timings plugin enhances the system logs by providing additional information about the durations of transactions taking place between the client and the server.
Push logs -- Consult the push log to track the status of push notifications that are queued to send from your system.
System email log -- The system email log records all emails that the instance creates or receives. System mailboxes are filtered views of this log.
Event logs -- The event log records all system events that occur within the ServiceNow AI Platform.
Import logs -- The import log displays information in a verbose format about any data import activity within the platform.
System Diagnostics module -- The System Diagnostics application provides logs that relate to the platform.
Customer Updates table -- Changes made in the system are recorded on the Customer Updates [sys_update_xml] table chronologically. There are a few exceptions, as noted below.
Log history -- The system uses table rotation and table extension to archive older logs.
Use the log file browser -- The instance provides the utilities log file browser and log file download.
Enhanced logging security -- Explore the Attribution field in the node log lines to identify the script or component that generated the log message. Transaction start lines include the new field to identify the type of request made.
Avoid log tampering -- Configure system log table protection rules to limit the scope of modification and deletion of application log records. The rules enable you to determine the logging of changes or attempts to changes in these tables.
Configuring the log protection plugin -- Configure the protection rules for each table and operation to complete the configuration of the log protection plugin.
Logging, auditing, and errors -- Apply a logging and auditing strategy so that you can identify and act on suspicious activity in a timely manner.
Disabling SQL error messages -- Use the glide.db.loguser property to disable SQL error messages from rendering in a browser.
Granular admin roles for Logging tables -- Granular admin roles replace broad admin access with targeted, feature-specific permissions. Use these roles to grant the administrative capabilities needed for specific tasks without assigning the admin role.
Secrets Management -- Secrets Management lets you control which applications and users can access sensitive credentials stored on your instance.
Exploring Secrets Management -- Use ServiceNow Secrets Management for granular management of access to your passwords to fit your business needs.
Create a secret group -- Secret groups organize secrets and apply access policies at the group level. Associate a secret group with an identity group to control MID Server access.
Secrets Management dashboard -- Use the Secrets Management dashboard to review the secret groups configured on your instance and learn about any security issues.
Create a basic secret group -- Create a basic secret group to group any secrets, regardless of their criteria.
Create a secret group with criteria -- Create a secret group with criteria to organize secrets entered in Password2 fields automatically when they share a common criteria, such as table, scope, or application.
Upload a public key -- Upload a public key to encrypt your secrets in Secrets Management.
Run jobs -- Schedule a Secrets Management job to perform encryption tasks on secrets fields on your instance.
Code Signing -- Use Code Signing to create digital signatures that prevent unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers. This cryptographic verification helps maintain the integrity of integrations between ServiceNow and external systems.
Explore -- Code Signing provides cryptographic verification to ensure that only authorized scripts can execute on MID Servers. Code Signing prevents unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers, maintaining the integrity of integrations between ServiceNow and external systems.
Configure -- Activate and configure Code Signing to verify the authenticity and integrity of your data.
Assign the Administrator Role -- Assign the Code Signing Administrator role to a user to access the Code Signing configuration experience.
Quorum Controlled Certificate Revocation -- The quorum-controlled certificate revocation for Code Signing certificates provides a secure mechanism for a Code Signing admin to revoke Code Signing certificates. The revocation process involves submitting a request that requires approval from multiple stakeholders. This workflow helps to prevent accidental or unauthorized revocations.
Export Request -- Start the certificate revocation process by selecting the certificate that you want to revoke. Provide the required configuration properties. Export this transaction as part of an update set, which is imported into the protected instance for approval and execution.
Import Request -- Import the update set into the protected instance to initiate the certificate revocation process. Approvers receive email notifications and they should complete the approval workflow before the certificate is revoked. The approval means that the revocations are confirmed, authorized, and traceable for security and compliance purposes.
Approve Request -- Review and approve certificate revocation requests from the email approval notifications that are sent to your registered email address. Review the approval notification and select the Click here to approve or Click here to reject link to access the protected instance and act. You can also access the approval request and the code-signing quorum request directly from the email.
Load Key Pairs and Certificates -- Establish the relationship in a designated trusted instance using Code Signing. This first step loads two cryptographic keys into the trusted environment to establish a trusted source for updates to the production instance.
Circle of Trust -- Create an update set in the trusted environment to export the trusted certificate to the production environment.
Manage Circle of Trust -- Retrieve the update set in production to establish the trust relationship between the two instances. The certificates that have been created to represent trust in the trusted instance must be accepted into the protected instance.
Turn on Code Signing -- Turn on Code Signing in your trusted non-production instance to identify the trusted instances linking to your production instance.
Create Key Pairs and Certificates -- Create two key pairs to signed certificates to establish trust between your protected and trusted instances.
Custom Firewall Rules -- Configure the External Communication Channel (ECC) firewall in your MID Server by specifying the custom rules to selectively allow or reject the incoming message and override the Code Signing configuration.
Root of Trust Settings -- Trust and use your own certificates instead of relying on ServiceNow build certificates (default) by changing to use your Root of Trust (ROT). ServiceNow components like script includes, business rules, etc., are signed at build time using a ServiceNow build time key (verification certificate is the ServiceNow build certificate).
Migrate Signatures -- Run a signing job to migrate your signatures to a customer Root of Trust (ROT).
Disable Root of Trust -- Run a scheduled job on your trusted instance to disable Root of Trust.
Using Code Signing -- Learn how to sign records, messages, and attachments to help verify the authenticity and integrity of your data.
Standalone Signing Tool -- Use the standalone Signing Tool to sign supported records in ServiceNow applications using your own private key.
Use Signing Tool -- Learn how to use the Signing Tool to sign supported records in ServiceNow applications.
Tool Arguments -- Learn about the available arguments for the Signing Tool.
JDBC Signing -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
Sign Existing Sources -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
Sign New Sources -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
REST and SOAP Signing -- Use update sets to sign and validate the REST and SOAP messages by enabling the code signing in protected and trusted instances.
Sign the Existing Messages -- Sign and validate the existing REST and SOAP messages by enabling the Code Signing in protected and trusted instances.
Sign the New Messages -- Sign and validate the new REST and SOAP messages from the trusted instance by enabling the Code Signing in protected and trusted instances.
Sign Records and Files -- Create a security job to sign specific records or attachments rather than all records or attachments on a table.
Sign Flows and Actions -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
Sign Existing Flows -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
Sign New Flows -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
Signature Verification -- Signature verification helps confirm that records, scripts, and other signed content originate from trusted sources and remain unaltered.
Health and Status Dashboard -- The Code Signing Health and Status dashboard provides a centralized, user-friendly view of your Code Signing environment's health and configuration. Use it to identify issues, verify configuration accuracy, and support secure, uninterrupted code-signing operations.
Dashboard Summary -- The Overview dashboard provides a centralized view of your Code Signing environment, offering real-time insights into key components and their status.
Signature Status -- View the status of valid, invalid, and missing signatures across different applications to assess code signing coverage. Use this information to identify areas that may require additional attention or action.
MID Server Configuration -- Manage and configure the trust relationships and certificate settings for MID Servers.
Key Pair and Certificates -- The Key Pair and Certificates dashboard displays details about the cryptographic keys and digital certificates used for Code Signing. It includes information such as key type, certificate issuer, expiration date, and validity status. Use this dashboard to manage code signing certificate credentials, verify their validity, and help ensure secure and trusted Code Signing operations.
Configuration Dashboard -- The Code Signing Configuration dashboard displays the system properties and key settings that control Code Signing in your environment, including flags and enforcement policies. These settings enable features, enforce signature validation, and define trusted sources.
Utilities Dashboard -- The Utilities dashboard provides a unified workspace to monitor signature status, detect configuration issues and maintain the overall health of your Code Signing environment. It consolidates common Code Signing administrative tasks into a single interface, eliminating the need to navigate across multiple areas of the instance.
Batch Signature Generator -- Automatically generate batch update sets for records with invalid or missing signatures on the trusted instance.
Administer and Troubleshoot -- Reference topics provide additional information to administer and troubleshoot Code Signing.
Properties -- Code Signing adds the following properties.
Roles -- Code Signing includes the following roles.
Admin -- Code Signing includes the following roles.
Manager -- Code Signing includes the following roles.
Auditor -- Code Signing includes the following roles.
Actions and roles -- Reference table of Code Signing actions, their descriptions, and the roles required to perform them.
Logs and Errors -- Access various logs to troubleshoot and identify the failure reasons.
Antivirus Scanning -- Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories.
Exploring Antivirus Scanning -- Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories.
Review antivirus activity -- Review the Antivirus Activities log that tracks all activities that occur on potentially-infected files from the point that they are discovered and placed into quarantine.
Understanding Dictionary attributes -- Dictionary attributes alter the behavior of the table or element that the dictionary record describes. As an administrator, you can set the values of dictionary attributes to modify the behavior of the default Antivirus Scanning configuration.
HTML sanitizer -- Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields.
Exploring HTML sanitizer -- Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields.
Configuring HTML sanitizer -- You must modify a script include to make configuration changes to the HTML sanitizer.
Enabling HTML sanitizer -- The HTML sanitizer provides a property to enable or disable the sanitizer for all HTML fields in the system.
Enable HTML Sanitizer logging -- When the HTML sanitizer removes elements or attributes, they are added to the system log.
Auditing -- Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others.
Exploring Auditing -- Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others.
Enable inclusion list auditing for a table -- Enable a table to audit only those fields you explicitly designate. This is useful when you want to audit only a small number of fields in an audited table.
Enable auditing for a system table -- Deletions from tables with a sys_ prefix are not audited by default. To track deletions from these tables, add the table name to the glide.ui.audit_deleted_tables property. Enabling the Restore Deleted Records plugin adds several default values to this property.
Audit Management Console -- Use Audit Management Console module to experience a more enhanced way of defining and configuring the audit capability within your instance.
Setup your audit retention -- Use the Retention option to automate and simplify the deletion of audit data as per your requirement.
Enable an audit deletion estimate -- Enable the audit deletion estimation feature that calculates the approximate number of records that will be deleted based on retention policies. This information helps you make an informed decision before applying a retention policy, which permanently deletes audit data and cannot be reversed.
Viewing Sys Audit and Audit Relationship Change tables -- The ServiceNow AI Platform tracks inserts and updates to audited records in the Sys Audit (sys_audit) and Audit Relationship Change (sys_audit_relation) tables.
Knowing about History sets -- The system automatically generates History Set records as needed from the Audit table when a user either creates a record or views its history.
Differences Between Audit and History Sets -- The Audit [sys_audit], History Sets [sys_history_set], and History [sys_history_line] tables store the same data, but they serve different purposes and manage data differently.
Control access to history -- You can give a role access to view audit history by setting a system property.
History List -- The history list displays each change as its own row in the change list.
History Calendar -- The history calendar shows you the days where the record was changed, who made the change, and when.
History Timeline -- You can view a timeline of changes for a CI and for its related records, relationships, baselines, and proposed changes for the CI. Timelines are available for CIs in the Configuration Item [cmdb_ci] table or a descendant of this table, if auditing is enabled for the tables.
Tracking inserts -- By default, the system does not create Audit records for inserts because in a typical instance, inserts can account for over 80% of the size of the Audit table.
Tracking CI Relationships -- Changes to a CI relationship (CI Relations, CI/User Relations, or CI/Group Relations) appear in the history of the items on both sides of the changed relationship regardless of whether the change was manual or a result of Discovery.
Granular admin roles for Audit tables -- Granular admin roles replace broad admin access with targeted, feature-specific permissions. Use these roles to grant the administrative capabilities needed for specific tasks without assigning the admin role.
High Security Settings -- High Security Settings refer to several security options available in your instance.
Activating High Security Settings -- The High Security Settings plugin is active by default on all new instances. If it is not active on your instance, you can request the plugin.
Virtual Private Network (VPN) -- Use a virtual private network (VPN) to integrate your instance with external data sources over the Internet.
Activating a VPN service -- For all VPN requests, including provisioning, modifications, or general questions, use the Service Catalog VPN Request form.
Configuring an address for VPN communication -- To prevent conflict or overlap with internal ServiceNow networks or with another customer's internal IP address schemes, the instance requires that all tunneled traffic in the encryption domain use non-RFC-1918 addresses on both sides of the tunnel.
Platform Privacy -- Privacy enables you to mask the sensitive date on the instance.
Exploring Data Privacy -- Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.
Data Privacy -- Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.
Data Privacy for Now Assist -- Set up and configure how to discover and anonymize sensitive data from generative AI prompts.
Configuring Data Privacy for Now Assist -- Configure a data privacy advanced configuration to de-identify personally identifiable information (PII) in generative AI applications.
Data privacy (Classic) -- Data privacy (Classic) is available as a family release. The last family updates were released in the Tokyo launch.
Activate data privacy (Classic) -- You can activate the data privacy plugin (com.glide.data_privacy) for Platform Security if you have the admin role. If the application doesn't include demo data or it doesn't install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they aren't already installed.
Create a data privacy policy -- Configure a data privacy policy to specify which data privacy techniques are used when anonymizing your data.
Configure a data privacy job -- Configure a data privacy job on your production instance to use anonymized data on your non-production instance for user and data class jobs.
Data privacy job rollback -- Database changes are captured for actions like jobs and scripts so that the changes can be rolled back. Roll back a data privacy job for when human error inadvertently anonymizes incorrect user information. The rollback de-anonymizes the data from the data privacy job.
Roll back a data privacy job -- Roll back a data privacy job on your non-production instance that uses anonymized data from your production instance to a state prior to de-identification of a data class or user job.
Data privacy clone -- As customer data are cloned from a source to a target instance, typically from production to non-production, sensitive data are de-identified on the target instance.
Configure data privacy clone request -- Data privacy clone integration is configured using a PostClone script to create and execute data privacy jobs for configured policies on the target. After running the script, users will see de-identified data and will not have access to the original data.
Data Privacy for Virtual Agent -- You can use Data Privacy to detect and mask the sensitive data and PII during a Virtual Agent conversation.
Data privacy -- The data privacy store app is a Next Experience refresh for data classification and data privacy with modern look, feel, and usability. Data privacy store app is supported in Utah and above.
Data privacy overview -- The Overview homepage is a starting point to manage your data and data privacy compliance.
Data classification -- Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.
Create data classifications -- Create your own user-defined data classifications in the [data_classification] table that you can then assign to specific columns in specific tables. Create new data classes to start the classification process.
Classify data -- Group data by type, using pre-defined or user-defined data classifications. Assign data classifications to specific table columns in the Dictionary [sys_dictionary] table. When you assign data classifications, it creates entries in the Dictionary-Data Class [m2m_dictionary_dataclass] table, which you can then review in the Overview dashboard.
Data anonymization -- Anonymization provides a way to easily transform data so that it is unidentifiable and more compliant with data privacy regulations.
Create anonymization techniques -- Create a data privacy technique configuration to customize how data privacy anonymizes your data.
Create anonymization policies -- Configure an anonymization policy to specify which techniques are used when anonymizing your data.
Configure data anonymization clone request -- Data privacy clone integration is configured using a PostClone script to create and execute data privacy jobs for configured policies on the target. After running the script, users will see de-identified data and will not have access to the original data.
Create anonymization job -- Configure a data privacy job on your production instance to use anonymized data on your non-production instance for user and data class jobs.
Activate parallel jobs -- Use parallel jobs to reduce your anonymization job execution time.
Anonymization of encrypted columns -- When creating data privacy policies, you may include columns that are also protected by Column Level Encryption (CLE). How you handle those columns depends on your organization's compliance requirements.
Real time anonymization -- Use the real time anonymization(RTA) policy to anonymize data entries in real time.
Real time protection -- Analyze user input in real time at the field level to identify sensitive data and alert users about potential sensitive data entry.
Real time protection policies -- You can configure policies to protect sensitive data in real-time through alerts and blocking actions.
User sensitive data logs -- You can view the top 100 activity logs for specific real-time protection policies that contain the most sensitive data from the last month.
Alert data patterns -- Before you can define real-time protection policies, you must create your alert data patterns; reusable groups of data patterns that detect and then alert or block sensitive data across your organization.
Attachment quarantine policies -- Manage policies that automatically isolate suspicious attachments for security review and analysis.
Attachment scan findings -- You can review the findings of your attachment quarantine scans, and work with any quarantined or alerted attachments.
Activate data privacy -- Data Privacy includes data classification and anonymization and is installed from the ServiceNow Store.
Domain separation -- If any conrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file. In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conref at the end that describes domain separation.Domain separation is unsupported for data privacy. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Data Discovery -- Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.
Exploring Data Discovery (Classic) -- Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.
Activating Data Discovery -- The application installs Data Discovery and related ServiceNow Store applications and plugins if they aren't already installed.
Classify data -- Classify sensitive data found by all successful jobs through Data Discovery Findings.
Data Discovery jobs -- Data Discovery reviews your targeted information using user-defined data patterns and target tables.
Configure a job -- Configure a Data Discovery job and review the status of ongoing jobs. A Data Discovery job defines when a pattern is executed on a target table.
Attachment scanning -- Attachment scanning in Data Discovery enables you to scan, discover, and report on sensitive data in file attachments.
Configure patterns -- Configure a Data Discovery pattern and review current patterns. A Data Discovery pattern defines the regular expression used to match data against a target table.
Default regular expression data patterns -- Review the default data pattern regular expressions included in Data Discovery. These default data patterns can be used to filter table entries for further classification.
Default NER data patterns -- Use Named Entity Recognition (NER) based discovery to help discover sensitive data that does not follow fixed patterns.
Using Text to RegEx with the classic UI -- Use the Generate Regex button and modal in the classic UI to automatically create a regular expression from a text description.
Configure target tables -- Add a target tables to be used in Data Discovery jobs. Only target tables will be scanned for data patterns.
Activate parallel jobs -- Use parallel jobs to reduce your Data Discovery job execution time.
Data Discovery roles -- You can assign Data Discovery roles to limit user access to certain data types.
Data Discovery job results -- The Data Discovery Findings page shows details on the data found by a job. You can use the Findings page to review the results of a job and begin classifying data.
Classify data in the Data Discovery job results page -- The Data Discovery Findings page shows details on the data found by a job. You can use the Findings page to review the results of a job and begin classifying data.
Scanning with Granular Configuration -- Granular scan can be used to scan specific table columns for discovery. Traditional Data Discovery jobs scan the entire table to discover data, whereas granular scan targets specific columns of the table thereby offers more control over the discovery process
Granular Findings -- Granular findings may be reviewed using the Granular Findings tool.
Data Discovery policies -- Use Data Discovery policies to scan specific tables and enable column based jobs.
Create a policy -- Create a Data Discovery Policy for granular control over your Data Discovery jobs.
Data Discovery Store -- Discover and track sensitive data within a ServiceNow instance
Data Discovery Store overview -- Get visibility into sensitive data on your instance and work towards implementing security measures to prevent loss or exposure of sensitive data.
Data Discovery policy -- Use Data Discovery policies to define what sensitive data patterns should be identified and how they should be handled.
Create new policy -- Create a Data Discovery policy to begin scanning tables for data patterns.
Data Discovery sources -- Create, and select the data patterns to be used in Data Discovery, and what tables to scan.
Using Text to RegEx -- Text to RegEx is an AI-powered capability that automatically generates regular expressions from natural language descriptions, helping you create data patterns without manual regex syntax.
Generate a regular expression using the discovery UI -- Use the Text to RegEx feature in the discovery UI to automatically generate a regular expression from a natural language description of the pattern you need.
Text to RegEx error handling -- When errors occur during regex generation or testing, Text to RegEx displays an error message to help you understand what went wrong and how to resolve the issue.
Licensing prerequisites for Text to RegEx -- Text to RegEx requires specific licenses to be active in your instance and relies on the Now Assist for Vault plugin. This reference describes all licensing requirements you must meet to use Text to RegEx.
Data Classification -- Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.
Installing plugin demo data -- When you upgrade to or install Australia (and above), the Data Classification (com.glide.data_classification) plugin is automatically activated. However, you should manually install the demo data that comes with the plugin. It includes several important pre-defined data classifications, and it also assigns one of them to specific User [sys_user] table columns in your instance.
Components installed with Data Classification demo data -- When you upgrade to or install Australia (and above), the Data Classification (com.glide.data_classification) plugin is automatically activated. However, you should manually install the demo data that comes with the plugin. It includes several important pre-defined data classifications, and it also assigns one of them to specific User [sys_user] table columns in your instance.
Creating data classifications -- Create your own user-defined data classifications in the Data Classification [data_classification] table that you can then assign to specific columns in specific tables.
Assigning data classifications to dictionary entries -- Assign data classifications to specific table columns in the Dictionary [sys_dictionary] table. When you assign data classifications, it creates entries in the Dictionary-Data Class [m2m_dictionary_dataclass] table, which you can then review in the Overview dashboard.
Analyzing data classifications -- The Overview dashboard reports the current state of data classifications within your instance and how your users are distributed by location.
Domain separation -- Domain separation is supported for Data Classification . Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Encryption -- Protect your sensitive data and stay compliant with regulatory requirements and standards.
Key Management Framework -- Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.
Exploring the Key Management Framework -- Learn about the components of the Key Management Framework (KMF), and how to use them to manage how cryptographic operations are performed on your instance.
Cryptographic module overview -- The Key Management Framework (KMF) is centered around managing Cryptographic modules. Use these modules to select a cryptographic mechanism and define where they're applied on your instance.
Cryptographic specification overview -- The Cryptographic specification is the component that defines aspects of your cryptographic module, including its cryptographic purpose and which encryption algorithm to use.
Module access policy overview -- Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.
Instance level keys in the Key Management Framework -- Learn about the Key Management Framework (KMF) key structure, which uses envelope encryption to ensure that all platform keys under KMF management are protected through a chain of keys. Customer Data Encryption Keys (CDEKs) created by KMF are also included in this structure
Configuring the Key Management Framework -- Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.
Assign Key Management Framework roles -- Administrators with the security_admin role can assign Key Management Framework (KMF) admins, who in turn can assign other Key Management Framework roles.
Configure field encryption settings to select key type -- Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.
Create a cryptographic module -- Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.
Create a cryptographic specification -- After you create a cryptographic module, create a cryptographic specification to define the module algorithms.
Configure key lifecycle states -- After you have created a cryptographic specification, you can configure the lifecycle actions for the keys in your instance.
Create a module access policy -- Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.
Create a cryptographic module life-cycle policy -- Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.
Key Management Framework Reference -- The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services.
Key Management Framework key life-cycle states -- KMF supports several cryptographic key life-cycle states through the enforcement of specific allowable actions. For example, only keys that are in the active state can be used fully for their intended cryptographic purpose. The following table provides further detail on the varying key life-cycle states.
KMF admin [sn_kmf.admin] -- The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.
Assign KMF roles -- The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.
Module access policy visualization -- Use module access policy visualization to view all relevant cryptographic module information on a single UI page.
Module access policy debugger -- Use the module access policy debugger to review logging information and understand why your users are or aren’t granted access to an encryption context.
Encryption and Key Management subscription bundle -- With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.
Key management actions -- One of the core features of KMF is to provide the capability to manage keys, such as revoking or rotating keys. KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.
View and manage keys -- Review the status of any key to determine further key action, such as when to renew, rotate, suspend, deactivate, or destroy a current key.
Rotate keys -- For increased security, you can rotate your cryptographic keys on a pre-determined schedule. Key rotation is when you retire an encryption key and replace that old key by generating a new cryptographic key.
Import a key from a web service -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
Import the wrapping / unwrapping key pair -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
Import a wrapped key from a web service -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
Key Management Framework Health -- Access on-demand health status information for the Key Management Framework. Warning and malfunction errors contain a detailed message.
Prepare your instance for GlideEncrypter deprecation -- Use an instance scan script to find and remove GlideEncrypter API calls on your instance. Removing these calls is a necessary step in deprecating 3DES encryption on your instance.
GlideEncrypter deprecation -- Learn how to remove the use legacy GlideEncrypter calls from the scripts on your instance.
Deprecate GlideEncrypter usage of 3DES for password2 fields -- Deprecate GlideEncrypter usage of 3DES encryption standard on your instance ensure that your instance uses the more secure Advanced Encryption Standard (AES) exclusively for the encryption and decryption of your Password2 data.
Key Management Framework Resource Exchange -- ServiceNow Resource Exchange is a KMF feature that gives you the capability to exchange resources between instances in a secure manner.
Key Management Framework Key Exchange -- KMF Key Exchange is a subset function of KMF Resource Exchange. Key Exchange securely transfers encrypted data across multiple instances.
Configure Key Exchange -- Key Management Framework (KMF) generates automatic key exchange requests for supported cryptographic modules during the fresh installation or upgrade of the instance, and manages the data encryption key locally for the instance.
Rekey ciphertext with Key Exchange -- Resource Exchange supports rekeying of ciphertext on the target instance that was encrypted with keys from the source. Rekey activity is tracked in the key life-cycle.
Recurring Key Exchange walkthrough -- Use this walkthrough to set up a recurring key exchange in your instance using and Resource Exchange.
Infrastructure Security -- Use Infrastructure security tools to create, upload, and manage certificates your instance uses to encrypt traffic from client to server.
Generate a Certificate Signing Request -- Use the Generate Certificate Signing (CSR) page to create a certificate signing request to support customer-signed certificates for your instance load balancer.
Password2 encryption with the Key Management Framework (KMF) -- Supported by the Key Management Framework, use the Password2 (2-way encrypted) field type to encrypt and decrypt custom fields with segregation of duties, key protection, and life-cycle management. It works in accordance with NIST 800-57 guidelines and provides FIPS 140-2-L3 protection.
FlowKMFEncrypter API -- The FlowKMFEncrypter API provides secure encryption and decryption for ServiceNow Flow Actions, using the Key Management Framework (KMF) crypto operations.
FlowKMFEncrypter in a Flow Action -- Resolve the "undefined is not a function" error that occurs when a Flow Action calls the FlowKMFEncrypter API, by allowing the operation in the Restricted Caller Access Privilege record.
Certificates -- Your instance requires certificates to establish secure connections and validate signatures.
Exploring Certificates -- Your instance requires certificates to establish secure connections and validate signatures.
Generating an LDAP client certificate -- Generate an LDAP client certificate for mutual authentication using OpenSSL. The final output is a PKCS#12 certificate stored within a Java keystore.
Generating a server certificate -- You can use keytool to generate a new Java keystore file, create a certificate signing request (CSR), and import the private key, public certificate pair, and signed certificates into the keystore.
Uploading a trusted server certificate -- By uploading the service provider's trusted server certificate, the instance ensures it is connecting to a valid and secure service.
Field Encryption -- Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.
Exploring Field Encryption -- Learn the details of Field Encryption Starter and Field Encryption Enterprise
Field Encryption Enterprise -- Field Encryption Enterprise uses the Key Management Framework (KMF) to enable you to customize and manage how fields and attachments are encrypted and decrypted on your instance. A subscription is required to use Field Encryption Enterprise.
Configuring Field Encryption -- Learn how to activate and configure Field Encryption and manage migration from Encryption Support.
Activate Field Encryption -- Activate either Field Encryption Starter or Field Encryption Enterprise.
Module keys for Field Encryption -- The Module Keys tab shows you summary level information about your Field Encryption Data Encryption Key(s). You can view the Key alias, Key type, Algorithm, Key lifecycle state, and Key version.
Wrap your customer-supplied key -- Wrap your symmetric data encryption key with an ephemeral public wrapping key before you can upload it to your instance.
Field Encryption and system clones -- Cloning an instance with Field Encryption installed automatically generates new field encryption module encryption keys on the target clone instance.
Prevent users from attaching unencrypted files -- Modify the com.glide.encryption.enable_attachment_key_ui property to prevent your users with access to an encryption module key from attaching unencrypted attachments.
Using Field Encryption -- Use Field Encryption to manage access to encrypted data on your instances.
Using multiple encryption modules -- Multiple encryption modules enable data to be encrypted with more than one encryption module. If each module has its own access policy based on a role, for example, users with different roles can encrypt data on the same table but used to help prevent them from viewing each other's encrypted data.
Encrypt data using Row Conditions -- Encrypt fields with multiple Field Encryption modules using Row Conditions to define the data being encrypted and the associated encryption keys. Row Conditions can also be used to define the users that have access using the condition builder.
Encrypt data using the Multiple Modules feature -- Encrypt data with more than one encryption module permitting the user to determine which keys are used for specific rows within the encrypted data.
Configure advanced algorithms for Field Encryption Enterprise -- Create a cryptographic specification to define the algorithm for a cryptographic module. Customize the encryption specifications with advanced options that are available for Field Encryption Enterprise.
Configure properties for customer-supplied keys -- If the Field Encryption Enterprise plugin is enabled, you can use system properties to define key padding, ephemeral key pair size, and a key validity period of your customer-supplied keys.
Encrypting fields and attachments -- Once cryptographic modules are created, a security admin can define the encrypted fields configuration (EFC) and opt to encrypt a field or attachment on a table.
Set encrypted field configurations -- Configure which table columns or attachments that the system encrypts using a preconfigured cryptographic module.
Configure script access to encrypted data -- Execute a script to run the cryptographic module policy for a cryptographic purpose. Specific read (decrypt/unwrap) or write (encrypt, wrap) access can be defined based on the module access policy operation granularity.
Run mass encryption or decryption -- You can run mass encryption on encryption configurations, as well as a mass decryption to decrypt previously encrypted values.
Upload attachments for encryption -- Protect sensitive files by encrypting record attachments using Field Encryption and Row Conditions.
Create a system module access policy -- Create a module access policy (MAP) for a matched user to encrypt attachments when inbound email processing runs as that user.
Create a user module access policy -- Create a module access policy (MAP) for a matched user to encrypt attachments when inbound email processing runs as that user.
Attachment encryption walkthrough -- These examples walk you through the encryption of fields and attachments using customer-supplied keys.
External Key Management Service -- External Key Management Service (EKMS) enables you to integrate Field Encryption with your own external key management systems.
Configuring External Key Management Service -- Set up External Key Management Service (EKMS) to control the encryption of your ServiceNow data using your Amazon Web Service Key Management System (AWS KMS).
Activate External Key Management Service -- Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.
Create Encrypted Field Configurations -- Configure specific fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.
Set up Module Access Policies -- Configure module access policies in External Key Management Service (EKMS) to control who can view encrypted data in clear text.
Change the status of an AWS KMS Key -- Modify the status of your Amazon Web Services Key Management System (AWS KMS) key and synchronize the status with your ServiceNow instance.
Change synchronization frequency -- Modify the system property to change how often External Key Management Service (EKMS) synchronizes Amazon Web Service Key Management Service (AWS KMS) key status with your instance.
Column Level Encryption -- Column Level Encryption permits and denies access to encrypted data based on user role. Column Level Encryption includes basic key management using encryption modules.
Column Level Encryption Guided Tour -- The tour gives a brief overview of the Column Level Encryption setup needed to encrypt table fields or attachments. Steps for the creation of Field Encryption Modules, Module Access Policies, and Encrypted Field Configurations are also covered. The tour includes links to detailed documentation and the ServiceNow University Column Level Encryption Overview course.
Column Level Encryption Enterprise -- Column Level Encryption Enterprise uses the Key Management Framework (KMF) to enable you to customize and manage how fields and attachments are encrypted and decrypted on your instance. A subscription is required to use Column Level Encryption Enterprise.
Configuring Column Level Encryption -- Learn how to activate and configure Column Level Encryption and manage migration from Encryption Support.
Prevent users from attaching unencrypted files -- Modify the com.glide.encryption.enable_attachment_key_ui property to prevent your users with access to an encryption module key from attaching unencrypted attachments.
Encrypt data using the Multiple Modules feature -- Encrypt data with more than one encryption module permitting the user to determine which keys are used for specific rows within the encrypted data.
Configure advanced algorithms for Column Level Encryption Enterprise -- Create a cryptographic specification to define the algorithm for a cryptographic module. Customize the encryption specifications with advanced options that are available for Column Level Encryption Enterprise.
Configure properties for customer-supplied keys -- If the Field Encryption Enterprise plugin is enabled, you can use system properties to define key padding, ephemeral key pair size, and a key validity period of your customer-supplied keys.
Encrypting fields and attachments -- Once cryptographic modules are created, a security admin can define the encrypted fields configuration (EFC) and opt to encrypt a field or attachment on a table.
Set encrypted field configurations -- Configure which table columns or attachments that the system encrypts using a preconfigured cryptographic module.
Configure script access to encrypted data -- Execute a script to run the cryptographic module policy for a cryptographic purpose. Specific read (decrypt/unwrap) or write (encrypt, wrap) access can be defined based on the module access policy operation granularity.
Run mass encryption or decryption -- You can run mass encryption on encryption configurations, as well as a mass decryption to decrypt previously encrypted values.
Column Level Encryption Enterprise walkthrough -- This walkthrough shows you how to encrypt a field in your instance using Field Encryption Enterprise with the Key Management Framework (KMF). It also shows you how to use your own key.
Attachment encryption walkthrough -- This walkthrough shows you how to encrypt an attachment in your instance using Field Encryption Enterprise with the Key Management Framework (KMF). It also shows you how to use your own key.
Cloud Encryption with Key Management -- ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle.
Key management operations -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Rotate a ServiceNow managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Prepare your customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Rotate a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Switch to a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Switch to a ServiceNow managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Schedule key rotation -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Withdraw a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Resupply a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
Quorum Control Policy -- The Quorum Control Policy specifies the minimum number of approvals required among the total number of selected approvers to reach quorum for customer managed key withdrawal.
Manage Quorum Control -- After a withdrawal operation workflow is triggered, quorum actions can be managed from the Key Management Operations page. The key withdrawal operation is blocked until the quorum is met.
Approve or deny a quorum request -- When a quorum request has been created, the minimum number of approvals is required by the members. After a withdrawal operation workflow is triggered, quorum actions can be managed using several methods. The users can grant approvals from the Key Management Operations page, My Approvals in the Instance, or directly from the request email. The key withdrawal operation is blocked until the quorum is met.
Key management transactions -- The Key Management Transactions submodule displays all transactions that have occurred for the keys in your ServiceNow instance.
Tamper Detection -- Use tamper detection to improve security by detecting unauthorized changes to your quorum control settings.
Full disk encryption -- Full disk encryption (FDE) applies encryption to the entire storage system within the database server only, because this is the only customer data-storing component. FDE protects only against physical loss or theft of storage devices. When encrypted disk servers are powered on and providing data, the encryption provides no additional protection.
Edge Encryption -- ServiceNow Edge Encryption encrypts sensitive data on your company premises before sending it over the Internet to your ServiceNow instance (encrypted in flight), where it remains encrypted at rest.
Exploring Edge Encryption -- Edge Encryption is a network encryption system that resides on your network and that encrypts and decrypts sensitive data as it travels between your data center and the ServiceNow cloud.
Edge Encryption components -- Edge Encryption is composed of the Edge Encryption proxy server that runs on a server in your network, and the Edge Encryption plugin that must be installed on your ServiceNow instance. If using order-preserving encryption types or encryption patterns, a proxy database must also be installed in your network.
Edge Encryption clients -- Edge Encryption uses three clients to inform the instance that the proxy is running, to synchronize requests between the proxy and the instance, and to forward all end user requests to the instance after any potential encryption.
SafeNet key versioning -- Use SafeNet key versioning to simplify changing keys. Instead of creating an alias for every new key, SafeNet key versioning keeps the same alias and increments the version.
Installed with Edge Encryption -- Edge Encryption installs tables to store encryption-related data, system properties to configure default behavior, and the edge_encryption role to administer Edge Encryption.
System requirements -- You can run the Edge Encryption proxy application on servers or virtual machines that run on Microsoft Windows or Linux operating systems. For optimum performance, ensure that your configuration meets these requirements.
Sizing your environment -- Choosing the number of proxy servers for your environment is an important task. Consider the number of users, redundancy needs, and acceptable latency.
Edge Encryption limitations -- Edge Encryption impacts system functions. Carefully evaluate the impact of encrypting a field.
Installing Edge Encryption -- You can install an Edge Encryption proxy manually or using the Edge Encryption interactive installer.
Request Edge Encryption -- The Edge Encryption plugin (com.glide.edgeencryption) is available as a separate subscription.
Set up an Edge Encryption user account -- The Edge Encryption proxies connect to the instance as a user to obtain and update encryption configuration information. Create a user account for this purpose and give the edge_encryption role to the user.
Download the Edge Encryption proxy server -- Download the Edge Encryption proxy server application from your instance, and then copy the file to each computer that is to run the Edge Encryption proxy server.
Configure CyberArk properties protection -- Optionally, configure CyberArk properties protection to securely store Edge Encryption passwords in a centralized and secure digital vault.
Configure the signature key -- Configure the signature key after installing the proxy server through the Edge Encryption proxy installer.
Configure the HTTPS certificate -- To enable clients to connect to the Edge Encryption proxy server using a secure SSL connection, import the HTTPS certificate to the proxy server.
Configure the AES 128-bit encryption key -- After you configure the HTTPS certificate through the Edge Encryption proxy installer, configure the AES 128-bit encryption key to encrypt your data.
Configure the AES 256-bit encryption key -- After you configure the AES 128-bit key through the Edge proxy installer, you can optionally configure an AES 256-bit encryption key to encrypt your data.
Update SSL certificate -- When updating an SSL certificate on an Edge proxy server, you must delete the old one.
Configure the proxy database -- If using order-preserving encryption types or encryption patterns, you can optionally configure the Edge Encryption proxy database properties.
Launch the proxy server -- After an Edge Encryption proxy is installed and configured, you can start the proxy from the installer.
Set up Unbound Technology keys -- Use Unbound Technology (previously Dyadic Security) keys with Edge Encryption by storing the base64-encoded wrapped encryption key as text file on the Edge Encryption proxy server and providing the wrapping key alias. The Unbound Technology implementation maintains control of the wrapping key.
Configure additional properties -- After installing the Edge Encryption proxy server in your network and setting up your keystore and keys, configure the additional Edge Encryption properties.
Configure a web proxy -- If your network uses a web proxy, you can set up the Edge Encryption proxy to use the web proxy.
Set proxy server memory limits -- Set the initial memory limit and upper bound memory limit to specify how much memory the proxy server can consume. Set these limits to avoid performance issues in your Edge Encryption implementation.
Start the proxy -- After an Edge Encryption proxy is installed and configured, you can start the proxy from the command line.
Obfuscate passwords in the properties file -- Obfuscate passwords in the edgeencryption.properties file to be able to share the properties file without revealing clear text passwords.
Manually add an additional proxy -- After the first Edge Encryption proxy is properly configured and tested, you can set up additional proxies on a Linux or Windows machine. Installing multiple proxies on the same machine is not recommended.
Authenticate a proxy server -- Specify that a proxy server is a trusted source so that Edge Encryption can process requests coming from that proxy server.
Stop the proxy -- You can stop an Edge Encryption proxy from the command line.
Uninstall the proxy on Linux -- You can uninstall the Edge Encryption proxy. If you are upgrading the proxy, it is not necessary to shut down and uninstall the current version.
Uninstall the proxy on Windows -- You can uninstall the Edge Encryption proxy. If you are upgrading the proxy, it is not necessary to shut down and uninstall the current version.
Set up multiple provider SSO -- Set up multiple provider SSO to enable logging in through the Edge Encryption proxy server URL or the instance URL. If you are implementing multiple provider single sign-on (SSO) with Edge Encryption enabled, some users might need to log in to your instance through the Edge Encryption proxy server, while other users might not.
Edge Encryption proxy server properties -- The edgeencryption.properties configuration file located in the /conf/ folder contains properties used to configure your environment.
CyberArk integration with the Edge proxy server -- Use CyberArk to store passwords in a centralized and secure digital vault to secure passwords that were previously stored in clear text and secured by file access, or that were previously encrypted via a second file.
Using a load balancer with the Edge proxy server -- You can use a load balancer to balance the load across the proxy servers in your Edge Encryption proxy setup. If the load balancer and proxy servers are using different ports, specify the host name and HTTPS port of the load balancer to enable users to view responses on their browser.
Configure the load balancer -- You can use a load balancer to balance the load across the proxy servers in your Edge Encryption proxy setup. If the load balancer and proxy servers are using different ports, specify the host name and HTTPS port of the load balancer to enable users to view responses on their browser.
Upgrading Edge Encryption -- Both instance upgrades and proxy server upgrades require special consideration in an Edge Encryption environment.
Schedule proxy server upgrade -- Create an upgrade schedule to enable the instance to upgrade an out-of-date proxy server.
Configuring Edge Encryption -- After the Edge Encryption proxy server is installed and running, manage Edge Encryption through the proxy server.
Rotate encryption keys -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
Schedule a single key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
Schedule a mass key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
Schedule an attachment key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
Change a field or attachment's encryption type -- You can change a field or attachment's encryption type by selecting a new encryption type in the existing encryption configuration record. A specific table and field combination can only have one active configuration at a time.
Repair or recover order-preserving encrypted data -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
Schedule an order token repair job -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
Schedule a proxy-database recovery job -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
Encrypt data from a record producer -- Configure your Edge Encryption proxy server to allow inserts from a record producer by creating encryption rules from the record producer record.
Define a custom encryption rule -- It may be necessary to identify and encrypt sensitive information in HTTP requests on the way to your instance. You can write encryption rules to identify, interpret, and encrypt data in such requests, mapping fields in the request to table-field names on your instance.
Inspect the client request -- Before creating a custom encryption rule, you must determine the format of the client request entering the Edge Encryption proxy server.
Create an encryption rule -- Encryption rules are used by the proxy to find content in HTTP requests that should be encrypted.
Encryption rule actions -- An encryption rule maps fields in a client request to fields in a table on your instance and identifies fields marked for encryption.
Encryption rule objects and APIs -- Use encryption rule APIs to parse and encrypt values in requests moving through the Edge Encryption proxy server to the instance.
request -- The request object is a global object available in Edge Encryption rule action and condition scripts.
request - getAsJsonContent() -- The request object is a global object available in Edge Encryption rule action and condition scripts.
request - getAsXmlContent() -- The request object is a global object available in Edge Encryption rule action and condition scripts.
request - XMLContains(String path) -- The request object is a global object available in Edge Encryption rule action and condition scripts.
POST and URL parameter APIs -- POST and URL parameters can be accessed as properties of the request object using request.postParams and request.urlParams.
ParameterValue - toString() -- POST and URL parameters can be accessed as properties of the request object using request.postParams and request.urlParams.
ParameterValue - getAsJsonContent() -- POST and URL parameters can be accessed as properties of the request object using request.postParams and request.urlParams.
ParameterValue - getAsXmlContent() -- POST and URL parameters can be accessed as properties of the request object using request.postParams and request.urlParams.
JsonNodeIterator -- You get a JsonNodeIterator object by calling the getIterator() or iterator() methods of the JsonNode class.
JsonNodeIterator - hasNext() -- You get a JsonNodeIterator object by calling the getIterator() or iterator() methods of the JsonNode class.
JsonNodeIterator - next() -- You get a JsonNodeIterator object by calling the getIterator() or iterator() methods of the JsonNode class.
print(String message) -- Prints a message to the wrapper log file: /logs/wrapper_.log.
Prohibited keywords -- The Edge Encryption proxy validates encryption rule scripts before saving the rule. Many JavaScript keywords aren’t allowed in encryption rule scripts.
Domain separation and Edge Encryption -- Domain separation is supported in limited circumstances with Edge Encryption. Edge Encryption provides the ability to encrypt data from within the customer's environment through the use of specific configurations, rules, and keys defined on the Edge Encryption proxy. The Edge Encryption proxy is not domain aware and cannot support domain-specific settings. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Data integration with Edge Encryption -- To integrate third-party data with an instance using Edge Encryption, you must route the data through the Edge Encryption proxy server using supported integrations. Supported integrations use base system encryption rules that map data in each payload to fields in a table.
ODBC driver integration -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
Import a self-signed certificate to the ODBC truststore -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
Set the ODBC driver properties -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
MID Server integration -- Configure the MID Server to route data through an Edge Encryption proxy server.
Diagnostics and performance -- Monitor Edge Encryption proxy server performance trends and drill into errors generated by the Edge Encryption proxy server.
Database Encryption -- ServiceNow offers database encryption (DBE) and full-disk encryption methods for customers with statutory obligations for data protection which may require at-rest protection for all data.
Exploring Database Encryption -- ServiceNow offers database encryption (DBE) and full-disk encryption methods for customers with statutory obligations for data protection which may require at-rest protection for all data.
Database Encryption with Customer Controlled Switch -- Database Encryption with Customer-Controlled Switch (DBE-CCS) is an encryption solution that encrypts all data-at-rest when not in use in the database.
Access Management -- Access Management enables you to have access to ServiceNow instance securely.
Zero Trust Access -- Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.
Explore ZTA -- Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.
Activating ZTA -- Activate the Zero Trust - Policy Based Session Access com.snc.zero_trust_session_access plugin to enable security admins to reduce or limit user access in a session based on IP address, location, Identity Provider attributes, and user attributes using adaptive authentication policies.
Configuring Session Access role -- Configure Session Access to reduce user access in a session based on IP, location, Identity Provider attributes, and user attributes using adaptive authentication policies.
System properties -- Use system properties to enable and customize Zero Trust Access to meet your security requirements.
Session Access Audits -- The Session Access Audits displays the Session Access logs and information related to a user's session.
Tutorial: Use ZTA -- Procedure to use Zero Trust Access feature with an end-to-end use case.
Configure IDP attribute for Session Access -- Use Identity Provider (IDP) attribute created from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) for removing or restricting user session access to the instance.
ZTA for Mobile -- Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.
Continuous Authentication (CA) -- ServiceNow's continuous authentication enables you to reverify and authenticate a user if they access resources that are protected by you.
Exploring CA -- ServiceNow's continuous authentication (CA) enables you to re-verify and authenticate a user if they access resources that are protected by you.
Policies -- View the different continuous authentication policies that are created.
Metrics -- View the different metrics for continuous authentication.
System properties -- Use system properties to enable and customize continuous authentication (CA) to meet your zero trust access security requirements.
Pre-work for CA -- Ensure to perform the following pre-work before using Continuous Authentication (CA).
Activating CA -- For activating the Continuous Authentication feature on your instance, install the Zero Trust - Continuous Authentication (com.snc.zero_trust_continuous_authentication) plugin.
Configuring CA -- Configure continuous authentication (CA) policies to re-authenticate the users if there's an attempt to access resources that are protected by you.
Tutorial: Configure CA for a Table -- Procedure that describes end to end configuration of continuous authentication policy for a table and the impacts to the users due to the configuration changes.
Tutorial: Configure CA for a Data Class -- Procedure that describes end to end configuration of continuous authentication policy for a data class and the impacts to the users due to the configuration changes.
High Assurance -- Establish high assurance session for with ServiceNow's continuous authentication.
SSO Login -- Establish high assurance session for SSO login using ServiceNow's continuous authentication.
Non-SSO login -- Establish high assurance session for non-SSO logins (local or LDAP) using ServiceNow's continuous authentication.
Audit logs -- Describes the details about Continuous Authentication (CA) logs. The CA logs displays all the authentication attempts performed by the users.
Domain separation for service providers -- With the ServiceNow Platform, service providers (SPs) can provide their customers with faster onboarding, meet compliance, and protect their data using domain separation. You can separate client data, processes, and reports into logical groupings called domains. SPs control who sees and accesses what content.
Exploring domain separation -- With domain separation you can separate data, processes, and administrative tasks into logically defined domains.
Delegating configuration options to customers -- Domain separation is designed to give ServiceNow service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.
Domain assignment -- By default, domain separation adds a domain field to tables and their extensions.
Visibility domains and Contains domains -- Visibility domains control what a specific user or group of users can see. "Contains" domains control what an entire domain of users can see.
Domain scope -- Domain scope defines what users can and cannot access.
Concepts for service providers -- These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.
Global queue v.2 -- The global queue concept provides a single virtual view of tasks that reside in multiple instances. The concept creates a custom application to provide a fulfiller view of work that resides in multiple instances without having to replicate tasks or data.
Service provider connector -- The service provider connector application is a reference design for creating a ServiceNow Store application for your customers to use to integrate with your systems. Service provider applications help you speed on-boarding and create standardized integrations.
Application support for domain separation -- Many ServiceNow applications support domain separation in the base system but not all. Some supported applications include limitations on the data and administrative settings that can be domain-separated. These definitions delineate the domain separation support levels from the perspective of actual use cases and the people who use them.
Domain separation explained -- With domain separation, you can segregate application data, UI, and business logic, such as rules or workflows, in a single customer instance. Separating these elements into logically defined domains supports specific hierarchies for all customers using your applications.
Value proposition -- With domain separation, service providers can have a multitenant instance architecture that delivers offerings efficiently and securely to their clients. Strong universal process standards, data-driven process design, strict governance, and centralized administration help to maximize these benefits.
Definition of domain separation -- With domain separation (also known as the ServiceNow Multitenant Platform Architecture), you can segregate application data, UI, and business logic in a single customer instance that supports hierarchical modeling with cross-tenant (customer) intelligence.
Domain separation hierarchies -- Create a hierarchy when defining a domain architecture to track your processes and workflows.
Context and domain separation -- The context of a user's session determines the processes, data, and user interface (UI) as the user browses through list views, home pages, reports, and knowledge articles. The context is determined by the processes that you create, the business rules that you set, your workflows, and other factors.
Segregating and securing data -- You can segregate and secure data on the ServiceNow platform in multiple ways, depending on your customer's needs.
Cross tenant intelligence -- A multi-tenant architecture is where you have a single instance serving multiple tenants. Data, metadata, business logic, and processing context for tenants is automatically handled with access to additional tenant data.
Alternatives to domain separation -- You can use a separate instance as an alternative to domain separation for your customers. A separate instance allows you the flexibility to meet the requirements for data separation within the groups and departments in an organization with little to no impact on others.
Evaluating the need for domain separation -- You may find that domain separation doesn't always work for your customers' organizations. It's best that you base your decision to go with domain separation by looking at your customers' needs.
Benefits of domain separation -- Domain separation may work better for your customers' organizations than any other method for separating the data between groups and departments.
How a database query works with domain separation -- Using database queries with domain separation in your customers' applications help them protect their data. These queries then speed up the configuration and build processes.
Domain separation levels of support -- Choose from three categories for domain separation of an application for your customers' organizations.
Service provider reference architecture -- Your customers can access service provider (SP) services by using a portal that is designed for them to reach their domain-separated instance.
Decision trees -- You can use decision trees and a comparison chart to determine if a new customer should be added to a shared instance or to their own dedicated instance.
Dedicated instances -- Service provider (SP) customers can access SP services by using a portal to a dedicated instance. SPs use these dedicated instances to manage their service delivery.
Hybrid solution -- Use the hybrid service provider (SP) reference architecture for a customized solution. Your customers require a dedicated instance for a specific service. They can still use the shared SP instance for other services, but it requires integration of each instance.
Service Integration Management (SIAM) -- The Service Integration Management Service Integration and Management (SIAM) for service provider (SP) architecture integrates services for a unified customer experience.
Domain separation terms -- With a ServiceNow instance, you can improve efficiency, add greater security, and increase performance for your customer organizations. It's helpful to understand some of the most common terms as you create your configurations.
Domain-separate a custom table -- You may need to create custom tables in separate domains. This topic covers both the procedure and the concept behind domain-separating a custom table.
Customizing domain properties and themes -- You can customize your customers' company properties and themes within the domains that you have configured. Customization makes their instances fit in with their companies' overall look and feel.
Managing domain separation for specific uses -- You can set up separate domains for email notifications and customize the properties of catalog, tables, users, groups, and views. This enables you to provide more specific behavior in each domain, giving your customers more flexibility.
Performance considerations -- As you configure domain separation in your application and services, make sure that you consider the number and properties of domains you create. Too many property-heavy domains can impact the performance of your instance.
Setting up domain hierarchies -- You can avoid slowdowns and performance impacts in your instance by knowing how domain hierarchies work and by setting them up properly.
Importance of the Default domain -- Organizing your domains is a crucial part of the domain separation process. If you don't set a default domain, new tasks and user records go to the global domain. Anyone can see the records in the global domain, which means that data can be seen when it is not supposed to.
Contains queries and domain access -- Use a "contains" query only in special cases, such as when users or groups need to see data from a domain that they don't have access to, but you don't want to move those users to a domain. Creating domain "contains" and user or group access for a domain should be an exception, only when absolutely needed.
Before Query business rules -- You can use a Before Query business rule to help support data segregation on an instance. ServiceNow applications that support domain separation may support the separation of data and data routing only, have advanced business logic separation, or support tenant (customer) level administration of the application.
Avoiding domain path in scripts -- Domain paths can cause the values of your script to change or even break, so don't use them in scripts.
Domain assignments -- How you assign a domain impacts the value of the sys_domain field. The assignments contain designs and business properties that affect how the application functions in each domain.
CSM plugin -- For the best outcome, be aware of how the properties in the CSM plugin work. When the plugin is enabled, you can see the status of your records in your domains.
Setup and administration -- Setting up domain separation involves requesting activation of a plugin, setting options, and assigning users and records to domains.
Request domain separation -- All domain support features are activated with a plugin called Domain Support - Domain Extensions Installer. Administrators can request activation of this plugin.
Domain separation plugin -- The Domain Support - Domain Extensions Installer plugin activates several domain separation features and properties at once. This plugin is typically referred to as the Domain Separation plugin.
Create a domain -- You can create a domain by creating a record in the [domain] table.
Make a domain the default -- Made a domain the default domain to which the system automatically assigns task and user records that are not already assigned to a domain.
Manually manage the domain for particular records -- By default, the system automatically assigns a domain based on the user's company record. In some cases, however, domain administrators want to manually manage which domain a particular record belongs to.
Domain Separated Tables -- You can see at a glance which tables are domain-separated in your instance with the Domain Separated Tables feature.
Domain Override Viewer -- With the Domain Override Viewer, you can see and manage all your process overrides at once across the entire instance.
Enable or disable a domain -- When you activate or deactivate a domain, the activation status cascades to companies within the domain.
Add a domain field to a table -- As an administrator, domain-separate a custom table by adding a sys_domain field to it.
View upgraded processes or records in the global domain -- You can track and review base system records or processes in the global domain that were overridden across one or multiple domains prior to an upgrade and were subsequently updated during a platform or app upgrade.
Review overridden records -- You can view information about specific overridden records and mark them reviewed.
View domain relationships -- The domain map offers domain administrators a read-only representation of the active domains on the instance and how they relate to each other.
Select a primary domain -- The primary domain indicates the top-level domain in the domain map.
Expand domain scope -- By default, when a user in the global domain views a table containing a sys_overrides column, the user sees records from only the global domain. When an admin in the global domain views a process table, that admin sees only records that are in that process table.
Add domains to a visibility domains list -- Adding a visibility domain allows a user or group to see and potentially edit records from another domain regardless of the user or group's normal domain membership.
Grant visibility domains to an individual user -- While it is possible to add visibility domains for specific users on the User form, it's best to add them only via groups. This controls permissions and access should individuals change departments or leave the company.
Enable domain selection menus in Core UI -- Displaying the domain picker in Core UI enables the domain selector by default. After enabling the domain selector, you can add a system property to enable the domain reference picker.
Application properties -- The Domain Separation plugin has two new tables to give service providers more flexibility in customizing their applications that use domain separation. These tables are the System Application Property table [sys_application_property] and the System Application Property Value table [sys_application_property_value].
Domain Migration Tool -- Use the Domain Migration Tool to move a customer from a domain-separated environment to their own dedicated instance.
View inactive audits -- You can view all inactive audits in one place and optionally activate them.
Security data filters -- Security data filters restrict access to records based on role, or security-attribute related assertions.
Create a security data filter -- Learn how to create security data filter rules to grant your users' access to records and tables.
Default security filters -- Generally data filters are applied after absolute ACLs (also sometimes called table-level ACLs), and after row-level ACLs. They are applied by default, and can be impactful to system behavior if not used carefully.
Authentication -- ServiceNow's authentication validates the identity of a user who accesses an instance, and then authorizes the user to features that match the user's role or job function.
Adaptive authentication -- Use the Adaptive authentication policy framework to enforce contextual authentication controls to the right users at the right time. Adaptive authentication uses authentication policies to evaluate authentication requests and then either deny or allow access to your instance based on the specified policy conditions.
Activate adaptive authentication -- You can activate the Adaptive Authentication plugin (com.snc.adaptive_authentication) for Adaptive Authentication if you have the admin role.
Filter criteria -- Filter criteria (also called policy inputs) are used as inputs for policy conditions to verify and meet the requirements of an authentication request.
IP Filter -- Use IP filter criteria to filter the users based on the user's IP addresses. Both IPv4 and IPv6 are supported.
Create IP filter criteria -- IP filter criteria allows you to filter users based on the user's IP addresses. You can configure an authentication policy to allow or deny access to a specific address or range of addresses.
Role Filter -- Use role filter criteria to filter users based on their roles.
Create role filter criteria -- Role filter criteria allows you to filter users based on the roles. You can configure an authentication policy to allow or deny access to a list of user roles.
Group Filter -- Use group filter criteria to filter users based on the user group to which the user belongs.
Create group filter criteria -- Group filter criteria allows or denies user access based on the user group to which the user belongs.
Location Filter -- Location filter criteria can be used as filter input for users based on the user location.
Activate Location Based Access -- Activate the Zero Trust - Location Based Access (com.snc.zero_trust_location_access) to allow admins to configure adaptive authentication policies based on the location of the user.
Create Location filter criteria -- Use location filter criteria to filter input for users authentication based on the user location.
Tutorial: Use Location Filter criteria -- Describes steps to use location filter criteria in the authentication policy and restrict access to the users based on the location.
Identity Provider Attributes Filter -- Use the Identity Provider attributes that are received from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
Attributes for SAML -- Use the Identity Provider attributes that are received from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
Use as filter criteria for SAML -- Use the Identity Provider (IDP) attribute from the Security Assertion Markup Language (SAML) response as a filter criteria for authentication policy.
Attributes for OIDC -- Use the Identity Provider attributes that are received from the OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
Use as filter criteria for OIDC -- Use the Identity Provider (IDP) attribute from the OpenID Connect (OIDC) response as a filter criteria for authentication policy.
Authentication policy contexts -- Use authentication policy contexts to determine how and when your instance enforces authentication policies.
Pre authentication context -- The pre authentication policy context defines how and when a policy is enforced during the login process. The policy used in this context executes before your users see a login screen.
Post-authentication context -- The Post Authentication policy context defines how and when a policy is enforced during the login process. The policy used in this context executes after your users see a login screen.
MFA context -- The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.
Account recovery context -- The account recovery context uses a policy to define how and when the account recovery can be established.
Session validation context -- Use the Session Validation Context as an additional layer of protection against session or cookie hijacking.
Activate session validation context -- Use session validation context to restrict access to ServiceNow when hijackers copy a user's session cookies from one device to another to impersonate the session or restricts the user's session access if they’re using an insecure network.
Tutorial: Configuring session validation -- Configure session validation within the Adaptive Authentication framework to provide as an additional layer of protection for session or cookie hijacking.
Authentication policies -- Authentication policies evaluate authentication requests based on the specified policy conditions and either allow or deny access depending on the output of policy conditions evaluation. For example, access is allowed only if all the policy conditions specified in Allow Access Policy evaluate to true.
Configure a policy -- Configure an authentication policy to define inputs and conditions to used to grant access to an instance or enforce multi-factor authentication.
Add to an authentication policy context -- Add an authentication policy to one of the authentication policy contexts. The authentication context uses the policy inputs and conditions to determine whether uses are granted access to the instance, or whether MFA is enforced for your users.
Configure properties -- After activating adaptive authentication, configure adaptive authentication properties according to your security requirements.
Certificate based authentication -- Certificate-based authentication lets you mutually authenticate inbound API requests using certificates from a trusted Certificate Authority (CA).
OAuth -- OAuth based authentication validates the identity of the client that attempts to establish a trust on the system by using an authentication protocol.
Token-based authentication -- Token-based authentication for inbound REST APIs configuration using API Key or HMAC.
Activate API Key and HMAC Authentication -- You can activate the plugin API Key and HMAC Authentication (com.glide.tokenbased_auth) in your ServiceNow instance.
Cleaning up token Expiry -- Details about how to clean up token expiry by using different system properties.
Basic authentication -- Legacy API authentication method using username and password, with restricted usage and varying behaviour in zBoot and upgraded instances.
Basic authentication restriction -- Basic authentication restriction is a security feature that controls which accounts can use basic authentication on a ServiceNow instance. Administrators can review identified users and assign per-account decisions before enforcement begins.
Basic authentication exceptions -- The Basic Auth Exceptions table lists accounts that have been identified as using basic authentication on the instance, along with their assigned decision and usage details.
API access policy -- API access policy defines the permissions and duration of access to an API.
REST API access policies -- REST API access policies allow you to restrict access to inbound REST APIs based on the authentication type and the specified filter criteria of the access policy.
Activate REST API access policy -- You can activate the REST API Access Policy plugin (com.glide.rest.policy) if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
Create an authentication profile -- Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.
Create REST API access policy -- Create an API access policy and map an authentication profile to restrict the authentication type for a REST API. For example, you can create an API access policy that allows only ID token authentication for a REST API.
API access policy prioritization -- Learn about the policy prioritization logic if there are multiple API access policy configured for your ServiceNow instance.
REST API Auth Scope -- Use the REST API Auth Scope to provide access to a specific REST API
Activate REST API Auth Scope -- You can activate the REST API Auth Scope plugin (com.glide.rest.auth.scope) to link the OAuth entity with authentication scopes.
Properties and tables -- The REST API Auth Scope plugin (com.glide.rest.auth.scope) includes the following system properties, tables, and scripts.
Configure auth scope -- Link the OAuth entity with an auth scope to manage the token to access the REST APIs that are linked with the auth scope.
Troubleshooting -- Troubleshooting actions can help resolve common issues when setting up or running the REST API scope.
SOAP API access policies -- SOAP API access policies allow you to restrict access to inbound SOAP APIs based on the authentication type and the specified filter criteria of the access policy.
Activate SOAP API access policy -- For SOAP API access policy, install the SOAP API Access Policy (com.glide.soap.policy) plugin.
Create an authentication profile -- Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.
Create SOAP API access policy -- Create an API access policy and map an authentication profile to restrict the authentication type for a SOAP API. For example, you can create an API access policy that allows only ID token authentication for a SOAP API.
Filter criteria for APIs -- Filter criteria contains filter conditions or queries that are used as policy inputs for an authentication policy. Policy inputs are used to group one or more filter criteria and define the policy conditions of an authentication policy. For example, an IP Filter Criteria define an IP address in the Classless Inter-Domain Routing (CIDR) format or a range of IP addresses.
API Authentication Policies -- Authentication policies evaluate authentication requests based on the specified policy conditions and either allows or denies access depending on the matching criteria.
Create a policy -- Authentication policies allow you to enforce access restrictions on the APIs based on the specified filter criteria.
Configure global blocking policy for APIs -- Global blocking policy denies the authentication requests of users and APIs based on the specified policy conditions. This policy can be used as an alternative to the IP Address Access Control.
System or Export Processors -- Ability for System or Export Processors to leverage processor access policy to secure all the export endpoints.
Authentication factors -- Authentication factors help identify and verify callers, allowing only authorized users to access AI voice agents on the ServiceNow AI Platform.
Explore authentication factors for AI voice agents -- Authentication factors are the elements used for caller identification and authentication. In secure voice agent environments, the process begins with identifying the caller, followed by authenticating their identity before granting access. A robust security strategy combines multiple factors to confirm that only authorized users interact with AI voice agents.
TOTP authentication -- A time based one-time password (TOTP) is a secure authentication factor that verifies user identity by generating a unique, time-sensitive code.
Push notification - Okta verify -- The Okta Verify app push notification enables users to securely approve authentication requests directly on their enrolled mobile devices.
Soft PIN authentication -- Soft PIN is a six-digit numeric PIN that verifies a caller's identity during an AI voice agent session.
Configure Soft PIN -- Users are required to configure Soft PIN before it can be used for authentication with ServiceNow AI Platform.
SMS OTP authentication -- SMS one-time password (OTP) authentication is a method used to verify user identity by sending a temporary, numeric code to the user's registered mobile number. The user enters this code to complete authentication.
Email OTP authentication -- Email OTP for AI voice agents sends a one-time numeric code to the caller's email address. The caller retrieves the code from their email and provides it to the agent to verify their identity.
Configure Email OTP -- Configure the Email one-time password (OTP) to enable OTP-based authentication for users in your instance.
Knowledge-based authentication -- Knowledge-based authentication (KBA) is an identification and authentication method that verifies callers by prompting them to answer preconfigured questions across conversational AI channels, such as AI voice agents. KBA can be used to identify a caller, authenticate a caller, or both within the same interaction.
Configure KBA -- Configure knowledge-based authentication (KBA) to identify and authenticate callers by prompting them to answer preconfigured questions across conversational AI channels, such as AI voice agents.
Create KBA questions -- Create knowledge-based questions to use for caller identification and authentication in AI voice agent interactions.
Create KBA answers -- Create knowledge-based answers for the preconfigured security questions to confirm the user's identity.
Map KBA questions to answers -- Create knowledge-based questions and answer mapping to confirm the user's identity.
Certificate-based authentication -- Certificate-based authentication lets you mutually authenticate user logins or inbound API requests using certificates from a trusted Certificate Authority (CA).
Set up -- Set up mutual authentication for either user interface-based logins or inbound web services.
Log in -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
Register client certificate for your PIV or CAC card -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
Log in to ServiceNow AI Platform using PIV or CAC card -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
Manage your client certificates -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
Custom instance URLs -- You can enable your ServiceNow instance to be accessible from a company-branded or custom URL.
Activate custom URLs -- Enable custom URLs to be set up on your ServiceNow instance. You can activate the Custom URL plugin (com.snc.customurl) if you have the admin role.
Set as the instance URL -- Add a custom URL to your instance configuration to use instead of your ServiceNow URL.
Identity Provider -- Set your custom URL with the Identity Provider to enable the user to login with their IdP's.
Datacenter job information -- Every custom URL that is associated to your instance has a corresponding ServiceNow datacenter job which runs and shows URL information that is pertinent to your instance as described in the table.
Generate SP metadata for SAML/SSO -- A SAML or SSO installation needs the SP metadata generated for the IdP before the custom URL instance generates.
Custom URL errors and fixes -- A list of common errors and associated fixes for a custom URL setup and configuration.Target Audience: ServiceNow Admin
Installation exits -- Installation exits are customizations that exit from Java to call a script before returning back to Java.
IP range based authentication -- One way to secure a web-based application is to restrict access based on the IP address.
IP Address Access Control -- Apply an IP access control to outbound traffic, inbound traffic, or bidirectional traffic. The system only blocks an IP address if a matching Deny rule exists and no matching Allow rule exists. By default, there are no restrictions on access to your instance.
LDAP integration -- An LDAP integration allows your instance to use your existing LDAP server as the primary source of user data.
Understand LDAP integration -- An LDAP integration allows your instance to use your existing LDAP server as the primary source of user data.
LDAP integration requirements -- Review the requirements for LDAP integration, which include a PKI certificate an LDAP compliant directory services server.
LDAP integration setup -- Administrators can enable LDAP integration to allow sign-on of users from their company LDAP directory.
Enable an LDAP listener and set system properties -- Enabling a listener is optional. If enabled, a listener notifies the system to process LDAP records soon after there is an update on the LDAP server.
Specify the LDAP attributes -- Specify the attributes included in LDAP server queries by using the LDAP server Attributes field. This can enhance performance as well as security.
Test an LDAP connection -- The instance tests the connection automatically every time a user opens the LDAP Server form. Alternatively, you can manually test the connection to the LDAP server from the LDAP server form.
Define LDAP organizational units -- An organizational unit (OU) definition specifies the LDAP source directories available to the integration.
Create a data source for LDAP -- Each LDAP organizational unit (OU) definition has its own related list of data sources.
Auto provision LDAP users -- You automatically provision users who are in the LDAP server but not yet in your instance.
LDAP integration via MID Server -- Administrators can integrate using an LDAP data source over a Management, Instrumentation, and Discovery (MID) Server.
Import binary data through a MID Server -- As an administrator, you can import binary large object (BLOB) data with an LDAP integration through the MID Server.
Verify LDAP mapping -- After creating an LDAP transform map, refresh the LDAP data to verify the transform map works as expected.
LDAP integration troubleshooting -- If you are integrating your LDAP server and have questions, these items may help you troubleshoot the issue.
View the LDAP monitor -- You can view current information about LDAP servers and listeners using LDAP monitor.
LDAP error codes -- The LDAP Log file lists industry standard error codes for both LDAP and Active Directory (AD).
Send a one-time password when the LDAP server is down -- An LDAP property is available to send a one-time password to a user if the user is unable to log in because the LDAP server is down. You can also configure another property to control how long the password is valid.
LDAP record synchronization -- Administrators can synchronize inactive, disabled, or deleted LDAP records with their LDAP records.
LDAP refresh filters -- Filters on the LDAP refresh process can be used to specify processing that ignores inserts of disabled users.
LDAP extraction -- Implement an LDAP extraction process to detect inactive users.
Inactive LDAP user accounts -- Detect that an existing, current, user account is inactive or has been disabled or deleted from an Active Directory (AD) LDAP.
LDAP script examples -- The following script examples assume you use an Active Directory (AD) for your LDAP server.
Active Directory Application Mode (ADAM) -- Active Directory Application Mode (ADAM) is an Lightweight Directory Access Protocol (LDAP)-compliant directory service.
Configuring an instance -- The first install copies the ADAM files to your computer, registers requires components, and creates the application shortcuts.
Set up the ADAM console -- Set up the ADAM console. Even though there are many similarities between ADAM and Active Directory, the administration can be very different since there is no Users and Computers management console.
Create containers and organizational units -- Logically group objects stored in ADAM into containers and organizational units (OU) just as they would be in Active Directory.
Delegation with ADAM -- Once the OU structure is created, define the permission delegations to properly secure the objects to limited users.
Populating ADAM Objects -- ADAM Objects include User Objects, UserProxy Object, and Group Objects.
Testing and troubleshooting -- The primary tool used for testing is LDP. This allows you to fully test user authentication.
Backup and recovery -- All ADAM data can be backed up using standard file system backup methods.
Use LDAPS with ADAM -- The default configuration for userProxy object authentication is to enforce LDAPS (secure LDAP) communications. LDAPS requires SSL certificates to secure the network traffic.
Assign the certificate to ADAM -- Install an SSL certificate on the server and any LDAP client to support secure binds and encrypt the user and password information being transmitted.
Export the public key certificate -- LDAPS clients, including the instance need the public key certificate in order to make a secure connection to ADAM.
ADAM access account -- The system requires a user account to read the Active Directory Application Mode (ADAM) object information that is imported into the application instance.
Test the LDAPS connections -- Test the LDAPS connections. There are two console connections, one for Local Computer Certificates, and the other for Local Computer Services Certificates on the new ADAM service.
Define ADAM user accounts -- Define user accounts in ADAM. One user account is used for the instance to connect with and the other user account is for ADAMSync.
Set up ADAMSync -- ADAMSync is included with Windows Server 2003 R2. Download and install ADAMSync if you are using a different OS.
Set up a stand-alone certificate authority -- The first step to configure Microsoft Active Directory for SSL access is to set up a stand-alone Certificate Authority (CA).
Test the LDAPS connectivity locally -- Test the LDAPS connectivity after installing the internal and third party certificates when you configure Microsoft Active Directory for SSL access.
LDAP global catalog usage -- A DC can be granted the Global Catalog (GC) role. Global Catalog (GC) role is an LDAP-compliant directory consisting of a partial representation of every object from every domain within a forest.
OpenLDAP minor schema modification -- In OpenLDAP 2.3 systems that use the back-bdb (Berkley backend), administrators make a minor modification to their schema to facilitate the integration.
Modify the schema -- Modify the OpenLDAP schema. These steps detail a schema modification to OpenLDAP 2.3 provided by one of our customers that helped them integrate with their instance.
Record LDAP deletions -- By default, the instance does not delete any entries after they disappear from LDAP.
Limit concurrent sessions -- You can limit the number of concurrent interactive sessions for a user or role on an instance across all nodes.
Explore limit concurrent sessions -- You can limit the number of concurrent interactive sessions for a user or role on an instance across all nodes.
Configure the plugin -- You can activate the Limit Concurrent Sessions plugin (com.glide.limit.concurrent.sessions) if you have the admin role.
Set a limit by user or role -- You can set a concurrent session limit on a specific user or on a particular role.
Employee self-service portal -- The system keeps track of the first starting page that a user is trying to access even if the user wants to log in to the Employee Self-Service Portal.
Specify a login landing page -- By default, users see their homepage upon login. You can specify a different login landing page by using a system property or the content management system.
Specify lockout for failed login attempts -- The system provides inactive script actions that enable you to specify the number of failed login attempts before a user account is locked and to reset the count after a successful login.
Enable password policies on your instance -- Implement password policy controls at login. Force users to change their password if the password does not meet the password policy criteria.
Password policy properties -- The password policy properties enable you to administrate password policies, exclude list passwords, and apply a password policy during login.
Configure your password policy -- Password policy criteria enables you to secure your password and adhere to the minimum password complexity requirements.
Configure password for a user -- Set your user's password for the instance based on the password policy that is configured.
Exclude passwords on your instance -- Add passwords to the Excluded Password table to prohibit specific passwords from being used by users on your instance.
Unsupported password characters -- There are password characters that are not supported. Users cannot use these characters, based on ServiceNow password complexity requirements.
Password Reset -- The default self-service Password Reset process enables a user to reset the password without assistance from service desk agents.
Modify notification email -- Users of the self-service Password Reset process receive an email notification when they request password reset. You can modify the text of the email and other aspects of the notification.
Configure properties -- You can specify properties that configure the Password Reset experience for end users.
Remember me -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
Change the default value of the Remember me check box -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
Remove the Remember me check box -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
Implement a nonce -- You can implement a nonce to be used with single sign-on digest authentication.
Nonce process flow -- When a customer has implemented the digested token Single Sign-on and wishes to add the security of a nonce, they follow a certain process flow.
Implement a nonce -- Add a cryptographic nonce to the authentication header to ensure that it can only be used once.
MFA metrics -- FAQ related to understanding the MFA metrics.
MFA types -- FAQ related to MFA types and why it’s important.
MFA reset -- FAQ related to MFA reset and why it’s important.
Exploring MFA -- Multi-factor Authentication (MFA) is an authentication method that requires users to provide information other than their basic credentials.
Configuring MFA -- Configure multi-factor authentication (MFA) to improve your users security posture when using ServiceNow.
MFA context -- The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.
MFA verification methods -- ServiceNow's MFA supports verification methods such as Authenticator App, Fast IDentity Online 2 (FIDO2) and Time-based One-Time Password (TOTP).
Web Authentication -- Use the Integration - Web Authentication (com.snc.integration.webauthn) to allow hardware key or biometric reader authentication on your instance.
Configuring with Biometrics -- Administrators can use the User Public Credentials list to view and manager user created credentials.
MFA with SSO -- You can use MFA with an SSO provider for your ServiceNow instance.
Configuring MFA with SSO -- Enforce MFA with SSO for your users within or outside your organization.
Reset MFA for users -- Administrators can reset MFA for users who deleted the app, lost access to the device, or have no alternative MFA associated with their device.
MFA References -- Reference topic related to the configuration of MFA.
MFA Metrics -- View the different MFA metrics to understand the MFA adoption and usage.
Using MFA -- Learn how to use multi-factor authentication tools to securely access your instance.
Set up MFA -- If your administrator enabled MFA on your profile but you have not yet set up the application, you can set it up upon login.
MFA Dashboard -- View the different MFA metrics to understand the MFA adoption and usage.
User Metrics -- User Metrics displays the user MFA enrollment trends on ServiceNow.
Log in Metrics -- Log in Metrics displays the log in trends on the ServiceNow.
MFA Guided Setup -- Use the MFA Guided Setup to step through the initial configuration of the MFA module and understand the requirements for MFA enforcements.
Multi-Provider single sign-on (SSO) -- External SSO allows organizations to use several SSO identity providers (IdPs) to manage authentication as well as retain local database (basic) authentication.
Activate Multi-Provider SSO -- This integration requires the Integration - Multiple Provider Single Sign-On Installer (com.snc.integration.sso.multi.installer) plugin.
Properties, tables, and scripts -- The Integration - Multiple Provider Single Sign-On Installer plugin includes the following system properties, tables, and scripts.
Multi-Provider SSO configurations -- You must perform several steps to set up Multi-Provider SSO, including configuring properties, creating identity providers (IdPs), and configuring users to use SSO.
Configure Multi-Provider SSO properties -- Configure SSO properties and also add a property to the System Properties table to configure an IdP inclusion list.
Create an external identity provider -- After you have configured the multi-provider SSO properties, you can update or create new SAML 2.0 or digest token identity provider.
Configure users for Multi-Provider SSO -- Administrators can configure Multi-Provider SSO for individual users or for all users who belong to a company. You cannot configure Multi-Provider SSO for groups.
Test IdP connections -- Testing the connection to an IdP validates the settings before enabling external authentication.
Common IdP connection errors -- The following table describes some of the common IdP connection errors and their solutions.
Troubleshoot script issues with SAML -- Troubleshoot script issues with SAML. You might encounter script issues if SAML is already active at the time that you activate Multiple Single Sign-On and if you already customized the installation exits.
Log in using Multi-Provider SSO -- The recommended and most efficient method for users to log in using Multi-Provider SSO is to use a specifically configured URL.
Account recovery (ACR) -- Administrators can configure account recovery (ACR) to perform recovery activities such as addressing SSO misconfiguration or expired certificates.
Configure an ACR user -- Configure an account recovery user to perform account recovery activities on your instance.
E-signature for Multi-Provider SSO -- E-signature with Multi-Provider SSO enables you to use the e-signature properties instead the SAML or OIDC properties for authentication.
Activate Approval with e-Signature plugin -- The Approval with e-Signature plugin (com.glide.e_signature_approvals) allows users to approve requests by re-entering their login credentials.
OIDC as a SSO identity provider -- OpenID Connect (OIDC) is an identity layer built on top of the OAuth protocol, which provides a modern and intuitive Single Sign-on (SSO) experience to you and your end users.
SAML -- The Security Assertion Markup Language (SAML) is an XML-based standard for exchanging authentication and authorization data between security domains.
Create self-signed BCFKS keystore for SAML -- Generate a FIPS 140-2 compliant self-signed BCFKS keystore for use in SAML signing and encryption operations within the Multi-Provider SSO plugin.
Install the identity provider certificate -- You can paste a PEM certificate into a X.509 Certificate form so the identify provider can verify communications with the service provider.
Replace a missing certificate for SAML -- If the Certificate module displays a blank page, the SAML 2.0 certificate record has been deleted. You can replace the missing certificate by manually creating a certificate record.
Test the SAML integration -- Test the SAML integration after you complete all the other setup tasks.
Clone an instance with a SAML integration -- Clone an instance with a SAML integration. Before you clone an instance that uses SAML 2.0, preserve the SAML SSO-related settings on the target instance or you might make the target instance inaccessible.
Typical SAML process flow (diagram) -- A typical SSO logic flow involves looking for an active session, checking user credentials, and creating the necessary token.
Login (AuthnRequest) process flow -- SAML 2.0 specifies a Web Browser SSO Profile that involves exchanging information among an identity provider (IdP), a service provider (SP), and a principal (user) on a web browser.
URL information for an SSO provider -- During a login challenge resulting from a URL link into the instance that requires an SSO session, the referring URL might need to be supplied to the SSO provider so that after authentication, the URL can be passed back to the instance and linked to the correct resource.
Add deep linking support for SAML -- Deep linking allows instances to support direct email links to a particular record in the system.
ADFS integration with SAML 2.0 -- The ServiceNow Multi-Provider SSO plugin supports a SAML 2. single sign-on (SSO) integration with Microsoft ADFS.
Set up ADFS for SAML -- Set up ADFS for SAML. This procedure uses ADFS 2.0 and shows samportal.example.com as the ADFS website. Replace this with your ADFS website address.
Configure an ADFS relying party -- Take the instance metadata and import it into your ADFS server. However, manual configuration of the relying party appears to be easier to implement.
Test the ADFS configuration -- Test your ADFS configuration to verify that it is properly functioning as an identity provider.
(Workaround) Enable service provider-initiated authentication -- Use this workaround if authentication fails because you do not have SAML 2.0 Update 1. This issue can happen if users attempt to skip IdP authentication and navigate directly to the instance.
(Workaround) Support Kerberos authentication -- A workaround is available for the SAML 2.0 integration that changes the authentication context from forms-based authentication to Windows-based authentication.
Email links with external authentication -- You can use email links when using the digestive token external authentication, however, you must establish how to handle links in email notifications.
Add E-Signature support for SAML -- Configure the following properties for E-Signature with Security Assertion Markup Language (SAML) 2.0 update 1.
Sample SAML 2 responses after the update -- The following sections illustrate the new required elements and attributes that the IdP should provide in the SAML Response.
SAML user provisioning -- If users exist in your IdP but are not in your instance, SAML user provisioning can automatically create the users in your instance's User [sys_user] table.
Administer SAML user provisioning -- Update the User table with the users in your IdP by first setting up field mapping and then enabling user provisioning through Multi-SSO IdP settings.
SAML 2.0 troubleshooting -- Before contacting support, try the troubleshooting solutions available in the knowledge base on Hi.
OAuth authentication -- OAuth based authentication validates the identity of the client that attempts to establish a trust on the system by using an authentication protocol.
OAuth 2.0 -- OAuth 2.0 lets users access instance resources through external clients by obtaining a token rather than by entering login credentials with each resource request.
Set up OAuth -- Set up and activate OAuth, enable the OAuth system property, create an OAuth application endpoint for external client applications to access the instance, and set OAuth parameters.
Activate OAuth -- By default, the OAuth 2.0 (com.snc.platform.security.oauth) plugin is active on new and upgraded instances. If the plugin is not active on your instance, you can activate it.
Set the OAuth property -- To generate OAuth 2.0 tokens to registered applications, the com.snc.platform.security.oauth.is.active property must be active for the instance.
Change OAuth password parameter -- Use this property to ensure only POST body parameters are accepted as input for all supported grant types.
OAuth Inbound -- OAuth Inbound authentication allows trusted external applications to securely access ServiceNow APIs, ensuring controlled and authorized connections.
Inbound Integrations -- The new inbound integration workflow in the ServiceNow Machine Identity Console provides enhanced experience for managing inbound integrations.
Auth Code Grant -- The OAuth authorization code grant is a secure and widely used flow for web, mobile, or desktop apps that access user data with user consent. It supports both private clients (using a client secret), and public clients (using PKCE).
Authorization Workflow -- ServiceNow handles both authentication and API access by acting as the authorization and resource server. When single sign-on (SSO) is enabled, it redirects users to the configured IdP for authentication and issues tokens after successful login.
Configuration -- Configure the OAuth authorization code grant to enable secure and interactive user authentication to enable applications to access resources on behalf of users. The OAuth authorization code grant verifies that the API access is granted based on the user identity and permissions.
Client Credentials Grant -- Use the OAuth client credentials grant type for back-end services or automated integrations that access ServiceNow APIs without user interaction. The client application authenticates directly using its client ID and secret, and receives an access token that represents the application itself, and not the user.
Client Credentials Workflow -- Authenticate a client application using a client credentials workflow. The client credentials grant workflow is used by back-end services or system integrations to access ServiceNow APIs without user involvement.
Configuration -- Configure the OAuth Client Credentials Grant for secure machine-to-machine authentication without user interaction. It authenticates applications using client credentials and grants-controlled API access with scoped permissions.
Third Party Token Grant -- The third party token grant enables ServiceNow to accept identity tokens from trusted external identity providers, such as Azure AD or Okta. Third party token grant provides secure, token-based access. This method supports secure access and single sign-on (SSO) in federated authentication scenarios.
User Token Flow -- This workflow can be used to integrate third-party identity providers (IdPs) with ServiceNow for secure API access. It allows client applications to obtain tokens directly from an IdP and use them to access ServiceNow APIs.
Service Token Flow -- Create a service account in ServiceNow to represent the identity of a third-party application accessing APIs through a trusted identity provider (IdP). This account maps the token claims to a user record and manages access with roles and permissions.
Configuration -- Configure a third-party ID token to enable secure authentication by verifying user identities through an external IdP. The third-party ID token improves security by reducing stored credentials, confirms seamless authentication, and supports interoperability with industry standards like OpenID Connect (OIDC).
JWT Grant -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction. Use this flow when a client application needs secure, unattended access to ServiceNow resources, either as itself or on behalf of a user.
Workflow -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction.
Configuration -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction. It enhances security with signed JWTs and reduces authentication overhead by eliminating repeated login attempts.
ROPC Grant -- Configuring an OAuth Resource Owner Password Credential (ROPC) grant enables applications to authenticate users by directly using their credentials to obtain an access token.
Password Grant Flow -- This flow is used in legacy or highly controlled environments where secure alternatives aren't feasible. The client app directly collects and sends user credentials to ServiceNow to obtain an access token, making it suitable only for trusted internal use.
Configuration -- Configuring an OAuth resource owner password credential (ROPC) grant enables applications to authenticate users by directly using their credentials to obtain an access token. This method is ideal for trusted applications and legacy systems that require authentication without browser-based flows, enabling secure token validation and controlled API access.
CIMD client integration -- CIMD lets the ServiceNow AI Platform accept an external OAuth client that identifies itself with an HTTPS metadata-document URL instead of a pre-issued client ID and secret.
CIMD workflow -- Configuring Client ID Metadata Document (CIMD) inbound support lets an instance accept an external OAuth client that's identified by a metadata document URL, without storing a client secret for that client.
Configure a CIMD client -- Register a Client ID Metadata Document (CIMD) client so that the instance accepts inbound OAuth requests from a client identified by a metadata document URL. You can fetch the client's configuration from its metadata URL or enter the details manually.
Update a CIMD client -- Update a registered Client ID Metadata Document (CIMD) client, including switching the metadata sync mode between Live and Static.
OAuth authorization code grant flow -- Authorization code grant flow allows a user to access a resource by authenticating directly with an OAuth server that trusts the resource, in contrast with authenticating with username/password credentials.
Configure an OAuth OIDC provider for accepting third-party token -- Configure an OAuth OpenID Connect (OIDC) provider to accept identity tokens generated by a third-party OIDC provider using inbound API calls using Single Sign-On option (Multi-Provider SSO).
OAuth implicit grants -- ServiceNow instances support the implicit grant of an access token.
Client Credentials -- Use the OAuth client credentials grant type for Inbound Integrations from a third party OAuth client to the ServiceNow platform.
Create the Client Credentials system property -- Create the glide.oauth.inbound.client.credential.grant_type.enabled system property to use Client Credentials grant type for OAuth inbound integrations.
Add the OAuth Application User -- Add the OAuth Application User field on the OAuth Entity form to use the Client Credentials grant type for OAuth inbound integrations.
Manage OAuth tokens -- Open OAuth tokens to provide access to restricted resources.
Revoke an OAuth token -- You might want to revoke an OAuth access or refresh token for security reasons.
OAuth Outbound -- OAuth outbound enables you to pull data from a third-party provider to your instance.
JWT Bearer -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention.
Set up OAuth provider with JWT Bearer grant type -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
Upload Java Key Store certificate -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
Configure a JWT signing key -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
Create a JWT provider with a JWT signing key -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
Generate a JSON Web Token (JWT) -- Create a JSON Web Token (JWT) for representing claims securely between two parties on the ServiceNow AI Platform.
OAuth client APIs -- The OAuth client API provides methods to request and revoke OAuth tokens.
OAuth parameters for default profile support -- The default profile feature requires a set of parameters that you can use with the setParameter() API to specify the OAuth requestor, a context for the request, and the provider profile.
Personal authentication -- Personal authentication enables you to securely connect and manage your OAuth-based integrations like Microsoft OneDrive or Google Drive.
Configuration -- You can configure personal OAuth authentication with the REST step in Flow Designer.
Get OAuth Token -- Check whether the user has a personal OAuth token. Use it to confirm valid access before running REST steps or integrations that require personal OAuth credentials.
Generate Auth URL -- Generate the initial token for a user who doesn’t have access to the credentials page to configure personal authentication.
Activate Dashboard -- You can activate the Personal Authentication plugin (com.snc.sn_ihub_personal_auth) for Integration Hub if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
Self-register to ServiceNow instance -- Use external user self-registration to on-board a large volume of external users to your instance. This feature enhances identity verification to improve customer experiences and supports commonly used registration flows.
Explore Self-register -- Use external user self-registration to on-board a large volume of external users to your instance. This feature enhances identity verification to improve customer experiences and supports commonly used registration flows.
Activate External User Self-Registration -- You can activate the External User Self-Registration plugin (com.snc.external_user_self_registration) if you have the admin role.
External roles in self-registration -- To prevent inadvertently providing access to external users, you can assign the snc_external role to all external users.
Configure a user registration configuration for external users -- Create a user registration configuration record to bootstrap the onboarding process of external users to custom ServiceNow applications. This form guides the external users through the self-registration process.
Verify user self-registration requests -- After a user registers from the Service Portal , a user record is added to the Registration Requests module. You can view the list of registered users who have successfully registered in the Service Portal .
Activate time limited authentication -- Time limited authenication activates through the Integration - Multiple Provider Single Sign-On Installer plugin.
Sample C -- This C class illustrates creating a digest token from three input parameters.
Web Embeddables -- Secure the web embeddables feature for authenticating the ServiceNow's web components that are used in third-party portals.
Configure client session access role -- The Embedded Session Role Configuration (Client Access Role configuration) record is created by default, which included removal of admin and security admin roles (high privilege roles) for the users using the UI components on the third-party portals.
Web service security -- Enforce security using basic authentication, mutual authentication, or WS-Security.
Explore Web service security -- Enforce security using basic authentication, mutual authentication, or WS-Security.
Access Control Lists -- Access control lists (ACLs) restrict access to data by requiring users to pass a set of requirements before they can interact with it.
ACL control of function fields -- When evaluating access to a function field, in addition to checking access to the function field itself, the system also checks access to the function's contributing fields. Contributing fields are those used as the arguments in a given function definition.
Security jump-start - ACL rules plugin -- The Security jump-start access control level (ACL Rules) plugin is installed automatically on all new instances. Use this plugin to quickly secure multiple system tables and expedite the production launch process for your organization.
Configure an ACL -- Configure custom access control lists (ACLs) to secure access to new objects or to change the default security behavior.
Allow ACL -- Learn about Allow ACLs (access control lists).
Query ACLs -- Query ACLs allow you to define more granular access control by explicitly defining who can query the data.
Secure records in an embedded list -- To apply security to the records in embedded lists, limit editing and deleting records in embedded lists to specific roles.
Related record access -- Related record access enable consistent control over what records users are able to access between related tables.
Contextual Security Manager -- Contextual Security Manager protects your data by controlling read, write, create, and delete authorization.
Prevent duplicate entries with Contextual Security: Role Management V2 -- Roles inherited from other roles are added as individual entries in the User Roles table [sys_user_has_role], potentially causing one role to have duplicate entries. Contextual Security: Role Management V2 eliminates these duplicate entries and prevents future duplicates.
Upgrade to Contextual Security: Role Management V2 -- Contextual Security: Role Management V2 is automatically installed on new instances. You can upgrade from Contextual Security: Role Management to Contextual Security: Role Management V2 to eliminate duplicate roles in the User Roles table and prevent future duplicates.
Double-check form submission -- When the system determines that a particular field (such as task.number) should not be written to by the current user, the system renders that field in a read-only mode, which is why the number field is not writable on most incidents.
Default deny property -- The default deny property (glide.sm.default_mode) controls the security manager default behavior when the only matching ACL rules are the wildcard table ACL rules.
Advanced ACL configuration -- In addition to creating new ACLs or modifying existing ones, you can configure other aspects of ACL functionality.
Provide external users access to a table -- To enable users with only the snc_external role to access the list view of a table, you must create a series of ACLs.
Apply ACLs to AJAXGlideRecord (client-side Glide record) -- Use a system property to perform access control list (ACL) rule validation when server-side records (for example, tables) are accessed using GlideAjax APIs within a client script.
ACL debugging tools -- Field level debugging and access ACL rule output messages are available to help you troubleshoot and debug ACLs. The ACL configuration watcher lets you know what related ACLs exist when you modify one.
ACL troubleshooting reference -- ACL troubleshooting includes identifying ACL rule errors and use the debugging tools to fix the ACL related problems.
ACL configuration watcher -- The ACL configuration watcher lets you know what related ACLs exist on a table when you insert, update, or delete an ACL on the same table.
Show ACL execution plan -- Administrators can view how ACLs relate to each other by viewing an execution plan for any ACL in the instance.
Access Analyzer -- ServiceNow Access Analyzer is an access diagnostic tool designed for AI administrators or creators to validate the access controls configured within various resources and agentic assets (agentic workflows and AI agents).
Access Analyzer Debug logs -- Access Analyzer debug logs supply detailed information about the evaluation of access controls for a specific operation. These logs assist administrators and developers in troubleshooting access issues, optimizing security configurations, and ensuring that users have appropriate access to resources within the ServiceNow platform.
Access simulator -- As a feature within Access Analyzer, you use access simulator to pre-validate the effects of adding or removing roles and groups for a specific user without actually implementing the changes.
Exploring Access Simulator -- Access Simulator helps you pre-validate how access to a specified table would change once a role or group is assigned or removed from the user.
Access Insights -- Access Insights helps you analyze or troubleshoot Role and Group entitlements through peer-level comparisons.
Exploring Access Insights -- Access Insights is a feature within the Access Analyzer application that provides data-driven recommendations and comparative analysis regarding user, role, and group entitlements.
Using Access Insights -- Use Access Insights to understand users' peer-level access to a selected resource.
Access findings -- Access Findings is the proactive detection and remediation layer within Access Management Console. It runs eight out-of-box access checks against your instance on a daily schedule, surfaces prioritized findings when misconfigurations are detected, and provides a complete remediation workflow.
Explore Access findings -- Access Findings runs eight out-of-box access checks against your instance on a daily schedule, letting you know when misconfigurations are detected. It also provides a complete remediation workflow that includes AI-powered guidance.
Use Access Findings -- You can use Access Findings to view the potential vulnerabilities that were discovered the last time access checks ran on your ServiceNow AI Platform.
Access management console -- ServiceNow AI Platform's Access management console ensures that the right individuals have the appropriate permissions to the right resources at the right time.
Explore Access management console -- Use the Access Management Console within Security Center to review and remediate access issues and misconfigurations. The Access Management Console provides enhanced visibility and control of your Access Analyzer findings, and streamlines remediation efforts. Within the console you can track, prioritize, and resolve access issues by assigning tasks.
Use Access management console -- Use the Access management console to ensure that the right individuals have the appropriate permissions to the right resources at the right time.
Security Attributes -- Security Attributes offer a flexible alternative to access control lists.
Security Attributes Fundamentals -- A Security Attribute is highly configurable piece of information about a Subject or it’s Environment, when used in access controls, enables fine grain security configuration in a non-complex way.
Compound Security Attributes -- Compound Security Attributes enable you to create consistent and reusable Security Attribute profiles suit your business needs
Create compound Security Attributes -- Compound Security Attributes enable you to create consistent and reusable Security Attribute profiles suit your business needs
Field Query Roles and Restrictions -- The Field Query Roles and Field Query Restrictionsattribute enable you to better control what information is available to users in tables.
Scripting Governance Tool -- Use the Scripting Governance Tool to provide a single, centralised control for managing scripting access across your ServiceNow AI Platform.
Explore Scripting Governance Tool -- The Scripting Governance Tool provides a single, centralised control for managing scripting access across your ServiceNow AI Platform.
Use Scripting Governance Tool -- Use the Scripting Governance Tool to provide a single, centralised control for managing scripting access across your ServiceNow AI Platform.
Scan for users who have scripted -- Scan your instance to find users who have scripted within a specific time frame. The scan queries the audit logs and identifies any user who has performed write or update to a table having script field.
Manage Scripting Governance Tool -- Enable or disable the Scripting Governance Tool on your instance by running the appropriate script. Only users with the security_admin role can run these scripts and modify the associated properties.
Machine identity access controls -- Define and enforce granular access control policies on specific resources for integration users.
Create a machine identity access control -- Enable administrators to define and enforce granular control for integration users by introducing User Access Profiles. This feature provides an additional layer of security and control, allowing admins to specify the exact resources (REST APIs and SOAP APIs) that an integration user can access, ensuring tighter governance and minimizing security risks.
Security Roles -- Security Roles provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
Explicit Roles -- You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
Request Explicit Roles -- You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
Elevated privilege roles -- Elevated privilege roles require you to manually accept the responsibility of using the role before you can access the features of the role.
Security_admin role -- The security_admin role is an elevated privilege role provided with High Security Settings that lets users create and change access controls and change High Security Settings.
Elevate to a privileged role -- The base system admin can elevate to a privileged role to have access to the features of High Security Settings.
Force administrators to manually elevate -- A property is available to force all users with the administrator role to manually select the role that they want to elevate to.
Connections and Credentials -- Credentials and connection information are required to gain access to a computer or network device for Discovery, Service Mapping, and Cloud Management or to perform work using Orchestration. When adding content to Share or AppStore, you can configure connections and credentials relevant to your environment without modifying built content.
Explore credentials, connections, and aliases -- All application integrations in the ServiceNow AI Platform use connections, credentials, and aliases to enable applications to access resources.
Scope protections -- You can classify certain types of Connection & Credential records as belonging to a scope, and extend scope protections to them. These scope policies protect records you create in a table, and prevent interactions with records that are private to another scope.
Domain separation and Credentials and Connections -- Domain separation is supported in Credentials and Connections. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
Connection & Credential configuration templates -- Enable users with the admin and flow_designer roles to set up spoke integrations with third-party systems using a single, customizable form.
Create a configuration template -- Create a template that defines the inputs required to set up a spoke. Set static key-value pairs to create records and set values that apply to every integration. Set dynamic key-value pairs to gather user input and set field values that may vary. Using this template, admins and flow designers can set up the spoke from a single form.
Get started with connections -- Use the connections table to set up a Basic, JMS, JDBC, or HTTP(s) connection to a target host.
Get started with credentials -- The MID Server uses the credentials you create in the Credentials [discovery_credentials] table to access resources for Discovery, Orchestration, Service Mapping, and Cloud Management.
Set up OAuth integration via MID Server -- Create a connection record that enables the sending of an OAuth token request to a third-party server via a MID Server.
Credential aliases for Discovery -- Credential aliases for Discovery allow an administrator to use specific credentials on Discovery schedules. You can configure behaviors for your aliases that determine how strictly the system enforces their use.
Create a Discovery credential alias -- Credential aliases for Discovery allow an administrator to use specific credentials on Discovery schedules. You can configure behaviors for your aliases that determine how strictly the system enforces their use.
Create and test your credentials -- Create and test the credentials that Discovery, Service Mapping, Cloud Management, and Orchestration require to access hardware and software in your network.
Ansible Tower credentials -- Ansible Tower credentials are required to access your Ansible configuration management account. Use these credentials to manage Ansible resources through the Cloud Management application.
API key credentials -- An API key is a unique code that is passed in to an API to identify the calling application or user.
Applicative credentials -- Some applications require credentials in addition to the credentials the that host machine requires. Credentials required to access these applications are referred to as applicative credentials.
Basic authentication credentials -- The basic authentication credential type manages access to store basic authentication credentials.
Chef server credentials -- Chef server credentials access chef integrations with the instance.
CIM credentials -- The CIM credential type manages access to a CIM server (also referred to as a CIMOM - Common Information Model Object Manager) for information about VMware ESX servers. This credential type is available for Discovery.
Configure NetApp storage devices for CIM credentials -- The CIM credential type manages access to a CIM server (also referred to as a CIMOM - Common Information Model Object Manager) for information about VMware ESX servers. This credential type is available for Discovery.
Cloud credentials -- Cloud credential types manage access to cloud-based applications, including Amazon Web Services and the Microsoft Azure cloud.
Container image repository credentials -- The container image repository credentials manage access to private repositories for container image scanning. This credential type is available for Discovery.
Infoblox credentials -- Infoblox credentials are required to set up IP pools (IPAM) in the Cloud Management application.
JDBC credentials -- The JDBC credential type manages access to a Java Database Connectivity (JDBC) connection. This credential type is available for Discovery and Orchestration.
JMS credentials -- The JMS credentials type manages access to a Java Message Service (JMS). This credential type is available for Discovery and Orchestration.
OAuth 2.0 credentials -- OAuth 2.0 credentials enable ServiceNow to obtain access to user accounts on an HTTP service.
SAP credentials -- The SAP credential type manages access to SAP JCo systems. This credential type is available for Discovery and Orchestration.
SNMP credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
SNMP community credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
SNMPv3 credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
SSH credentials -- Discovery, Orchestration, and Integration Hub explore UNIX and Linux devices by using SSH credentials to execute commands over Secure Shell (SSH). SSH commands must run with root privileges, either with root credentials or through the use of sudo. SSH private key credentials provide additional security.
VMware credentials -- The VMware credentials type manages access to vCenter credentials.
Windows credentials -- Windows credentials provide access to Windows computers. This credential type is available for Discovery and Orchestration.
Credentials troubleshooting -- Review the section of the ECC queue payload to troubleshoot issues with credentials.
External credential storage -- An instance can store credentials used by Discovery, Orchestration, and Service Mapping in an external credential repository rather than directly in a ServiceNow credentials record.
CyberArk credential storage integration -- The MID Server integration with the CyberArk vault enables ServiceNow Orchestration, ServiceNow Discovery, and ServiceNow Service Mapping to run without storing any credentials on the instance.
CyberArk integration configuration -- These procedures include both CyberArk and ServiceNow configuration tasks, including references to the appropriate CyberArk documentation.
Configure CyberArk for SNMPv2 credentials -- If your system uses SNMPv2, you can create a special file to map the attribute in a credential to the community string.
OAuth 2.0 authentication via MID Server using external credential storage -- Store OAuth 2.0 credentials-client ID and client secret-in the CyberArk vault instead of the ServiceNow instance. The MID Server gets the credentials from the CyberArk vault, when required to get the OAuth token. The token is stored in the MID Server and refreshed automatically upon expiry.
Configure a JAR file and credential identifiers -- Configure a JAR file and credential identifiers so that the JAR file resolves the credential identifiers into actual credentials from the CyberArk external vault. The process enables the MID Server to get and include OAuth 2.0 credentials in the OAuth token request.
Configure CyberArk -- Configure the CyberArk vault to store OAuth 2.0 credentials and respond to requests for OAuth 2.0 credentials from the MID Server.
Configure a connection to send OAuth request via the MID Server using external vault -- Configure a connection to send requests for OAuth 2.0 tokens to a third-party auth server via the MID Server. The MID Server adds OAuth 2.0 credentials (Client ID and Client Secret) from the CyberArk external vault, OAuth scope, and token URL from the instance to the request and sends them to the third-party auth server.
ServiceNow access control -- The SNC Access Control plugin (com.snc.snc_access_control) enables you to control which Customer Service and Support employees can access your instance, and when.
Explore ServiceNow access control -- The SNC Access Control plugin (com.snc.snc_access_control) enables you to control which Customer Service and Support employees can access your instance, and when.
Configure ServiceNow access control -- Configure an access control record to specify one or more Customer Service and Support employees who have permission to log in your instance.
Audit logging -- The following logging tracks logins and activity by ServiceNow employees.
Identity -- Know more about the Identities in the instance.
Global Identity -- Use ServiceNowGlobal Identity to help identify and manage users across multiple instances.
Exploring Federated ID -- The ServiceNow Identity system deduplicates users across multiple instances using their User ID and email, and assigns each resolved user a unique Federated ID for consistent identification.
Accessing Federated ID Criteria -- Access Federated ID Criteria to see the ID fields selected to generate the Federated ID unique identifier. The default setting is User ID and email.
Updating ID fields -- To generate new Federated IDs, you can either use the existing user resolution search criteria or update the criteria before regeneration.
Identity and Access Audit -- Use the Identity and Access Audit to understand changes made to users, groups, roles, and ACLs.
Identity Metrics for administrators -- View trends of the users, privileged users, active sessions, and integrated account on your ServiceNow instance.
Machine Identity Console -- Manage your service accounts which are used for integrations with ServiceNow.
Inbound integrations -- Inbound Integrations in the machine identity console allows you to configure and manage external applications to access ServiceNow APIs.
Security findings -- Provides Machine Identity security score and findings.
Accounts with no login for 100 days -- Display the findings about the accounts that have not accessed any API in 100 days under the Security findings in the Machine Identity Console.
Accounts using Basic Authentication -- Display the findings about the accounts that are using only basic authentication to authenticate the APIs under the Security findings in the Machine Identity Console.
Integration accounts with Web Service Access set to false -- Display the findings about the accounts that are authentication ServiceNow with the Web Service Access set to false under the Security findings in the Machine Identity Console.
Accounts performing both UI and API login -- Display the findings about the accounts that are performing UI and API login under the Security findings in the Machine Identity Console.
Activating Machine Identity Console -- Activate the Machine Identity Management com.glide.identity.machine_identity_management to manage your service accounts which are used for integrations with ServiceNow.
Using Machine Identity Console -- Manage your service accounts which are used for integrations with ServiceNow using the Machine Identity Console.
Role masking for AI agents -- Role masking for AI agents and agentic workflows helps administrators enhance security by limiting the roles those agents use during tool execution, and by verifying that AI agents run with least-access privileges.
System for Cross-domain Identity Management (SCIM) -- The System for Cross-domain Identity Management (SCIM) API provides endpoints to create, read, update, and delete operations on users and groups using the SCIM protocol.
SCIM Provider -- The Service Provider provisions users and groups using the SCIM API.
Exploring SCIM Provider -- The Service Provider provisions users and groups using the SCIM API.
Activating the SCIM plugin -- For SCIM activation, install the SCIM v2 - ServiceNow Cross-domain Identity Management (com.snc.integration.scim2) plugin.
Provisioning user using Basic Authentication -- Configuring SCIM automatically provisions and de-provisions users and groups to ServiceNow by using the providers' provisioning service with Basic Authentication.
Provisioning user using OAuth -- Configure the provider for SCIM automatically provisions and de-provisioning of users and groups to ServiceNow by using the providers provisioning service with OAuth.
Create a SCIM Extension schema -- Create custom attributes to map to fields that are not mapped as part of either the core schema or the ServiceNow extension schema.
Create a SCIM ETL definition -- Use the SCIM ETL definitions to map the custom attributes with the sys_user or sys_user_group tables.
Handling unmapped fields -- You can handle unmapped fields in SCIM customization in different ways.
Creating a source definition -- Create a source definition to capture information about which identity source a resource is provisioned from.
SCIM Client -- The SCIM Client facilitates provisioning and updates on identity resources through CRUD operations exposed by SCIM endpoint on an external system.
Exploring SCIM Client -- The SCIM Client facilitates provisioning and updates on identity resources through CRUD operations exposed by SCIM endpoint on an external system.
Activate the SCIM Client plugin -- For SCIM Client activation, install the SCIM v2 - ServiceNow Cross-domain Identity Management Client (com.snc.integration.scim2.client) plugin.
SCIM Client properties, tables, scriptable APIs, and logs -- The SCIM v2 - ServiceNow Cross-domain Identity Management Client (com.snc.integration.scim2.client) plugin includes the following system properties, tables, scriptable APIs, and logs.
Create a REST message -- Configure a REST message for all outbound calls for a particular SCIM Provider.
Create a SCIM Provider -- Create a SCIM Provider to fetch resource types and schemas information from the SCIM Provider with the REST message. Enable the configuration of the HTTP Method (PUT or PATCH) to update a resource in the SCIM Provider.
Create a SCIM Provider Resource Mapping -- Define the mappings of SCIM attributes to ServiceNow attributes for a particular resource type and SCIM Provider.
Create a SCIM attribute mapping -- Create a SCIM attribute mapping and use it as a single source of resource to the ServiceNow table fields.
Attribute Mapping references -- The attribute mappings enables you to use the attributes as a single source of resource to the ServiceNow table fields.
SCIM Client troubleshooting -- Troubleshooting actions can help resolve common issues when setting up or running the SCIM Client.
Access observer -- Use Access Observer to understand people and processes access data on your instance.
Configure access observation -- Create an access observation record to review access to a data column during a specified time window.
Review Access Observer logs -- Use information in the Access Observer log records for insights on how your data is accessed.
Granular admin roles -- Granular admin roles enables you to verify proper access management by assigning roles that define user permissions and responsibilities. By doing so, organizations can maintain security, enforce conformance, and optimize their operations effectively.
Platform security granular admin roles -- Use granular admin roles to verify access management by assigning roles that define user permissions and responsibilities.
Additional resources -- If you’re looking for Platform Security best practices, troubleshooting, or other implementation guidelines, select a feature or resource type to discover ServiceNow resources on other relevant websites.
Virtual infrastructure security -- Use virtualization with the flexibility to install multiple MID Servers in virtualized operating systems and networks in shared physical hardware.
Operating system security -- Learn how the MID Server stores its ServiceNow AI Platform username and password in its configuration file, named config.xml, for secure authentication to the instance.
Network security -- The MID Server communicates on port 443 using SSL to the instance and requires no inbound connections.
Agentic AI security and governance -- Now Assist AI agents operate securely within the boundaries you define. Layered controls govern who can invoke each agent, what data it can access, how interactions are monitored, and how your organization retains oversight.
Permissions-based access control -- Use Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.
Data protection -- Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.
Governance and admin safeguards -- Find guidance on preparing your instance for AI deployment, maintaining domain separation, and reducing risk across your Now Assist implementation.
AI threat protection -- Learn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using Now Assist Guardian.
External AI agent security -- Learn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.
Now Assist Guardian -- Now Assist Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.
Configure prompt injection attack protection -- Activate or deactivate prompt injection attack detection settings to protect all generative AI interactions on your instance from malicious inputs and unintended model behaviors.
Configure sensitive topic filters -- Set up filters in Now Assist Guardian to redirect Virtual Agent users to a live agent or HR case when a sensitive subject is detected in a conversation.
Export Now Assist Guardian logs -- Export logs from Now Assist Guardian to get insights into how often different guardrails are being detected and used.
Configuring a Guardrail Service Provider -- Now Assist Guardian supports default guardrails and third-party or custom guardrail service providers to extend AI content monitoring with your organization's AI governance policies.
Create a custom guardian -- Create your own custom guardian to monitor and detect requests sent to LLM.
Setup a Guardrail Service Provider -- Select a guardrail service provider of your choice in Now Assist Guardian to monitor and detect Now Assist interactions for harmful, offensive, and prompt injection content.
Assess readiness -- Verify that your instance is prepared for AI agent deployment, install the required applications, assign the required roles, and classify user identity types before you begin building.
Plan your agent -- Define your use case, decide between an base system and custom agent, choose an activation model, and set your success criteria before you begin building.
Build your agent -- Create your agent in AI Agent Studio, configure its tools and knowledge sources, and set the access controls that determine who can invoke it and what data it can access.
Configure security controls -- Set up Now Assist Guardian guardrails and data privacy controls to protect your AI agent interactions before testing begins.
Test and validate -- Test your agent's execution and access controls, run automated evaluations, and review Guardian logs before approving the agent for production deployment.
Go live and monitor -- Deploy your agent to production, activate analytics and monitoring, and establish the ongoing review cadence that keeps your agent performing securely over time.