Skip to content
Release: Australia · View source

Australia Platform security

  • Secure your instance -- Platform security provides capabilities to secure the instance.
  • ServiceNow Vault -- ServiceNow Vault provides a single location to review and implement data security tools, including encryption, data discovery and classification, anonymization, zero trust access, and log export, to protect sensitive data across its entire lifecycle.
  • Exploring ServiceNow Vault -- Learn more about ServiceNow Vault and review the benefits it can provide for your data protection needs.
    • AI in ServiceNow Vault -- With the Now Assist for Vault application, you can automate many tasks in Vault with the help of AI. These tasks include securing custom applications to improve your security posture, checking role access for an encrypted column to monitor your instance’s encryption access posture, and others.
    • Vault Suite -- Vault Suite deploys the complete set of ServiceNow Vault capabilities on your instance automatically, eliminating manual plugin setup.
  • Configuring ServiceNow Vault -- Learn how to install and configure ServiceNow Vault.
    • Install ServiceNow Vault -- Install the ServiceNow Vault application and assign the required roles.
    • Install Vault Suite -- Use Vault Suite to deploy ServiceNow Vault and its underlying plugins in a single step, without configuring each plugin separately.
    • Vault roles -- Learn and set up the roles necessary to use ServiceNow Vault.
    • Install plugins -- Learn how to review and install the necessary plugins for ServiceNow Vault.
    • Install Now Assist for Vault -- Install the ServiceNow Now Assist for Vault application from the ServiceNow Store to get Now Assist for Vault.
    • Use guided setup -- Use guided setup to configure an application with ServiceNow Vault.
  • Use agentic AI -- Use the Now Assist for Vault agentic workflows to complete tasks autonomously.
  • Use generative AI skills -- The Now Assist for Vault application includes the generative AI skills and features that enable you to streamline your administrative workload.
  • ServiceNow Vault console dashboard -- Use the ServiceNow Vault console dashboard to track and manage your ServiceNow Vault security tools.
    • Tools and metrics -- Learn about the tools and metrics ServiceNow Vault uses to protect and discover sensitive data.
    • Default policies and configurations -- ServiceNow Vault has a set of ready-to-use policies and configurations for selected tools to help you get started quickly.
  • Now Assist for Vault -- With Now Assist for Vault, you can generate custom data patterns, check role access for an encrypted column, and schedule data discovery jobs. Now Assist for Vault can make it easier for you to perform common tasks without going to multiple systems.
  • Platform Security -- Platform security provides capabilities to secure the instance.
  • Security Center -- ServiceNow Security Center is an application that consists of a set of tools designed to help your organization maintain the security of your ServiceNow deployments. Using Security Center, you can improve security posture and strengthen compliance levels with a seamless user experience.
    • Security Center landing page -- Use the Security Center landing page to find the information and tools you need to secure your instance.
    • Security Tasks -- Use Security Tasks to monitor, prioritize, and assign all your security-related tasks in one place.
    • Automatic Security Task generation -- Learn about how and when your instance generates Security Tasks.
    • Edit Security Tasks -- Learn how to create, edit, delete, or export Security Tasks in Security Center
    • Export Security Tasks -- Learn how to export Security Tasks into files you can download and use in other software.
    • Security posture console -- Improve your ability to identify, respond to, and recover from security threats with comprehensive visibility and step-by-step instructions.
    • Security Best Practices -- Use Security Best Practices to implement privacy and security configuration tasks on your ServiceNow instance.
    • Security posture dashboards -- Use the customizable single and multi-instance security posture dashboards to monitor your security KPIs. These dashboards consolidate the important information regarding the security of your instances in a single location and include a number of base system dashboard widgets.
    • Access Management -- Use the tools in the Access Management section verify that your data is only accessible to the users and processes that need it.
    • Security configuration console -- Use the security configuration page to get an overview of the security posture of your instance. View your hardening compliance score, discover graphical trends, analyze the top non-compliant hardening settings, and see the results of your security scans.
    • Security hardening -- View your hardening compliance score, compare it with previous scores, and change settings to improve your compliance score and security posture in the security hardening page.
      • All settings -- Review all of your instance hardening settings available from a single page.
      • Hardening settings details -- Analyze the details of a hardening setting by selecting its link within the Security Center app.
      • Filter hardening settings -- Simplify your hardening review process using filters. These filters can create a working list of hardening settings for review, which restored for later use and shared with other users.
      • Hardening compliance score trend -- View the trends of your hardening compliance score over time in a chart or table.
      • Increase score -- Increase your hardening compliance score by ensuring that the hardening settings are compliant with the system's recommendations.
      • Hardening score comparison -- Gain visibility to the health of your hardening settings and use this data to improve the security posture of your instance.
    • Security scanner -- Scan your instance against a set of security checks to identify misconfiguration. The scanner tool simplifies the process of creating different suites of checks for different use cases so that you can analyze the results over time.
      • Scan findings -- A finding is a reference to a record that has violated a rule from a check on the instance. You can find the source record and additional information about the triggered rules, and how to resolve the finding.
      • Security scan comparison -- Compare two scans of the same security suite to gain visibility to the health of your hardening settings and improve the security posture of your instance.
      • Scan findings trend -- Review Security Center scan findings over time.
      • Scan checks -- Use checks to detect anomalies within an instance, running against tables, records, or metadata.
      • Scan suites -- Review details on the scan suites available on your instance.
      • Access Controls Auditor checks -- Learn about the checks available in the default Access Controls Auditor Suites, what criteria they evaluate, and how they can be used to improve the security of your instance.
      • Security Center Scan Suites -- Use the Auditor suite to SecureCheck to detect misconfiguration that can impact the security posture of your instance.
      • Create a scan suite -- Create and schedule a custom suite so that you can analyze the security of your instance for your organization.
      • Reschedule a scan suite -- Change the schedule of your scan suites to suit your needs.
      • Scan results -- View data related to your scan results from a single view.
    • Customer Actions -- Use the Customer Actions tool to implement important security updates based on your instance and the configuration of plugins.
    • Security monitoring console -- Supervise security notifications and metrics to stay informed about potential security risks on your instance.
    • Security Event Notifications -- View, manage, and analyze the default security event notification policies on your ServiceNow instance, as well as access the functionality to create custom policies.
      • Create custom policies -- Learn how to create custom security event notifications that are specific to your organization's needs. This enables you to monitor actions taken by users and groups on your instance and generate notifications for potential security risks.
      • Modify policies -- Learn how to modify the settings of your security event notification policies.
      • Configure policy preferences -- Discover how to customize security event notification policies in Security Center to align with your organization's specific needs.
      • Create custom email -- Learn how for creating a custom email for security event notifications by configuring new notifications, setting triggers, defining recipients, and crafting email content with dynamic event fields.
      • Security Event Notifications history -- Explore the complete history of security event notifications on your instance.
    • Security metrics -- Monitor over 50 different Security Metrics to identify potential security threats or insecure behaviors. Set thresholds for email notifications, visualize, and analyze the data in multiple ways. Export the data, or create dashboards with the metrics that are most important to your organization.
      • Customize the dashboard -- Discover the flexibility of the My security metrics dashboard, which can be customized with metrics from various sources like graphs and charts. Tailor the dashboard to suit your organization's specific requirements.
      • Configure email notifications on threshold triggers -- Learn how to configure Security Metrics so that your instance generates an email notification when a threshold is triggered.
      • All Security Metrics -- Navigate to All Security Metrics to view a table with the data related to the Security Metrics of your instance.
      • Active Sessions -- View the trend line of the active users on the ServiceNow AI Platform.
      • Adaptive authentication Security Metrics -- Use authentication policies to evaluate authentication requests and deny or allow access to your instance based on the specified policy conditions.
      • Antivirus -- Displays the trend of when events occur on potentially infected files. See when they are discovered, placed into quarantine, restored, or deleted.
      • Authentication -- View trends for metrics related to authentication schemes, such as Multi-Factor Authentication(MFA) use, web service accounts, and biometric scanner usage.
      • Data Classification -- Access the Security Metrics for data classification on your ServiceNow instance.
      • Authentication metrics -- View metrics related to authentication on your instance from a dashboard.
      • Email -- Displays data related to spam emails that are being received externally.
      • Export -- Discover the data that is commonly exported, and which users do the exporting.
      • Integration Accounts -- View the trends about the integration accounts that are created on the ServiceNow AI Platform.
      • Privileged Identity -- Analyze data related to metrics for users with privileged identity.
      • Privileged Users -- View the trend line for the privileged users (active and inactive) and their activity on the ServiceNow AI Platform.
      • Session management -- View metrics related to user sessions and the frequency of lockouts of the sessions.
      • Users -- View the trend line for total users (active and inactive) and their activity on the ServiceNow AI Platform.
    • Security learning -- Access security learning materials from a single page.
    • ServiceNow Security Center announcements -- Enable security banner announcements and notifications to stay informed about urgent and critical security alerts using high visibility banners visible to administrators within the instance UI.
    • Granular roles for Security Center -- Use the new Security Center admin role to grant users security center administrative capability without using the admin role.
  • Instance Security Center -- Monitor the compliance level of instance security controls, view security event monitoring metrics, and configure and maintain instance security settings all from within the Instance Security Center. The Instance Security Center consolidates several key security components into a single control console that helps you detect, protect, and respond to instance-based security events.
    • Migrating to Security Center -- Learn the key differences when migrating from Instance Security Center (ISC) to ServiceNow Security Center (SSC).
    • Monitor security events -- Analyze the event metrics in your instance so that you can identify and prevent potential security events.
    • Configure the security event ribbon -- Configure the security event ribbon on the Instance Security Center homepage to include only those events that are relevant for tracking instance security in your operations. You can also change the order in which the security event tiles appear on the ribbon.
    • Set preferences for security event notifications -- Configure preferences for the types of notifications you want to receive for occurrences of specific security events. For each type, you designate whether to receive notifications by email, by push notification in Now Mobile, or in third party messaging applications such as Slack or Microsoft Teams.
    • Check the daily compliance score and configure security property settings -- Review the Daily Compliance Score metric and security configuration properties to see if your instance complies with the suggested security requirements. You can affect the daily compliance score by updating non-compliant security properties in the Hardening Compliance Configurations page.
    • Adjust instance security settings to increase compliance -- Using the Hardening Compliance Configuration page, harden and optimize non-compliant security properties that affect the daily compliance score of your instance. Its use ensures that your instance complies with the published security hardening standards, while fulfilling your company's security requirements.
    • How Daily Compliance score, trend, and graph data is refreshed -- Trend and graph data in the Instance Security Center is updated after the performance analytics job executes at 02:00 local time. It appears in the Daily Compliance Score tile, in the Event ribbon tiles, and in the KPI Details page detail.
    • PCI compliance score dashboard -- The PCI compliance score dashboard shows how your instance conforms to payment card industry (PCI) security standards. Use the dashboard to view your compliance score and modify your configuration to improve security.
    • PCI configuration controls score dashboard -- Use the PCI configuration controls score dashboard to review your PCI configuration and determine which security checks are non-compliant. You can change the configuration of the non-compliant security checks from the instance security center.
    • Scan for incorrect security definitions -- Run the Auditor to scan your instance and find incorrect security definitions. It provides findings you can correct to help improve the security posture of your instance.
    • Monitor instance metrics -- Monitor user, export, authentication, email, and antivirus metrics for your instance. For example, you can monitor your email security by checking metrics for spam, external emails, and inbound emails from untrusted and trusted domains for your instance. Analyze these metrics to look for anomalous security behaviors that are related to activities that take place in your instance.
    • User metrics -- Analyze user metrics to look for anomalous behaviors that are related to specific types of user activity in your instance.
    • Export metrics -- Analyze export metrics to see what data is most commonly exported and which users export the most data.
    • Authentication Metrics -- Analyze authentication metrics to see information related to authentication, such as infrequently used IP addresses, failed logins, and types of authentication schemes used by your users.
    • Adaptive authentication metrics -- Analyze adaptive authentication metrics to monitor and add insights on how adaptive authentication is being used on your instance.
    • Email metrics -- Analyze your email metrics to look for anomalous behaviors that are related to the incoming emails to your instance. For example, if the metrics indicate a spike in spam emails from specific domains, you can define inbound actions that prevent their delivery to the instance.
    • Antivirus metrics -- If the Antivirus Scanning plugin is activated, Antivirus Scanning runs in your instance to help protect it against virus infections from attachments.
    • MFA metrics dashboard -- The MFA metrics dashboard shows information on your instances multi-factor authentication configuration. Use the dashboard to ensure your MFA configuration meets your security standards.
    • Activate the ISC Virtual Agent interface -- If you have the admin role, you can activate the ISC Virtual Agent Conversations plugin (com.glide.isc_virtualagent). Activating this plugin installs the Virtual Agent and Natural Language Understanding (NLU content packs, providing Virtual Agent access from the Instance Security Center.
  • Hardening settings -- The ServiceNow Security Center (SSC) hardening settings content contains detailed descriptions and compliance values for the security-related system properties and plugins in the ServiceNow AI Platform. You can set these properties using the hardening settings app in the Security Center.
  • Log Export Service (LES) -- Log Export Service (LES) lets you seamlessly export your instance system and application logs into your enterprise security analytic tools.
    • Explore -- The LES service provides a highly scalable and near real-time integration with your analytic tools that is easy to set up and maintain. If you're new to LES, read this overview section to learn what the tool can do.
    • Log sources -- Log Export Service (LES) can export log sources from some System Log Tables, the Audit Table, and Application Node Log Files.
    • Administer -- Use LES to create log source configuration and multi-topics for each source type.
    • Create a log source configuration -- Regulate and set filters on the logs to be forwarded by creating a log source configuration.
      • Create source type and multi topics in the LES source table -- Consume logs for each source type by creating multiple topics per source type. You can now leverage the option of customized selection of specific topics for different log sources during the debugging process, without impacting the other log tables.
    • Update system property -- Update the glide.les.disable_logs_forwarding system property within the Log Export Service application to control log forwarding during migration or database reseeding operations.
    • Configure -- Use guided setup to step through the initial configuration of LES. Guided setup assists you with planning the roll-out of the product and performing the basic configuration to go live.
    • Kafka consumer -- Use guided setup to step through the initial configuration of LES for Kafka consumers.
    • MID server consumer -- Use guided setup to step through the initial configuration of LES for MID server consumer.
    • Secure Hermes LES connection -- Secure your Kafka topics by generating a ServiceNow instance-signed certificate.
    • Use -- Use LES to review the log report dashboard.
    • Review log report -- Use LES to review the log report dashboard.
    • Reference -- Find all the miscellaneous information about LES in the reference section.
    • Log Export Service roles -- Log Export Service is installed with these roles.
  • Logs -- Logs module provides a variety of logs that you can use to troubleshoot and debug transactions and events that take place within the instance.
    • System logs -- The System Logs module provides a variety of logs that you can use to troubleshoot and debug transactions and events that take place within the instance.
    • System log -- View warnings and errors for instance processes, records, and non-critical events, such as memory usage on the server machine.
    • Disable stack trace formatting in system logs -- Enable viewing original unformatted log messages by disabling the collapsible stack trace formatting in system logs.
    • Transaction logs -- The transaction log records browser activity for an instance. To aid in debugging of system issues, you can filter transaction logs by application scope, limiting transactions that appear to only those transactions originating in specific scopes.
      • Client transaction timings -- The Client Transaction Timings plugin enhances the system logs by providing additional information about the durations of transactions taking place between the client and the server.
    • Push logs -- Consult the push log to track the status of push notifications that are queued to send from your system.
    • System email log -- The system email log records all emails that the instance creates or receives. System mailboxes are filtered views of this log.
    • Event logs -- The event log records all system events that occur within the ServiceNow AI Platform.
    • Import logs -- The import log displays information in a verbose format about any data import activity within the platform.
    • System Diagnostics module -- The System Diagnostics application provides logs that relate to the platform.
    • Customer Updates table -- Changes made in the system are recorded on the Customer Updates [sys_update_xml] table chronologically. There are a few exceptions, as noted below.
    • Log history -- The system uses table rotation and table extension to archive older logs.
    • Use the log file browser -- The instance provides the utilities log file browser and log file download.
    • Enhanced logging security -- Explore the Attribution field in the node log lines to identify the script or component that generated the log message. Transaction start lines include the new field to identify the type of request made.
    • Avoid log tampering -- Configure system log table protection rules to limit the scope of modification and deletion of application log records. The rules enable you to determine the logging of changes or attempts to changes in these tables.
    • Logging, auditing, and errors -- Apply a logging and auditing strategy so that you can identify and act on suspicious activity in a timely manner.
    • Disabling SQL error messages -- Use the glide.db.loguser property to disable SQL error messages from rendering in a browser.
    • Granular admin roles for Logging tables -- Granular admin roles replace broad admin access with targeted, feature-specific permissions. Use these roles to grant the administrative capabilities needed for specific tasks without assigning the admin role.
  • Secrets Management -- Secrets Management lets you control which applications and users can access sensitive credentials stored on your instance.
  • Code Signing -- Use Code Signing to create digital signatures that prevent unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers. This cryptographic verification helps maintain the integrity of integrations between ServiceNow and external systems.
    • Explore -- Code Signing provides cryptographic verification to ensure that only authorized scripts can execute on MID Servers. Code Signing prevents unauthorized or tampered External Communication Channel (ECC) queue records from being processed by MID Servers, maintaining the integrity of integrations between ServiceNow and external systems.
    • Configure -- Activate and configure Code Signing to verify the authenticity and integrity of your data.
    • Assign the Administrator Role -- Assign the Code Signing Administrator role to a user to access the Code Signing configuration experience.
    • Trusted Instance Setup -- Turn on and configure Code Signing on your trusted instance.
    • Upload configuration files to your protected instance -- Upload the configuration file generated on your trusted instance.
    • Protected Instance Setup -- Turn on and configure Code Signing on your protected instance.
    • Enable Certificate Validation -- Protect your instance with certificate based validation.
    • Quorum Controlled Certificate Revocation -- The quorum-controlled certificate revocation for Code Signing certificates provides a secure mechanism for a Code Signing admin to revoke Code Signing certificates. The revocation process involves submitting a request that requires approval from multiple stakeholders. This workflow helps to prevent accidental or unauthorized revocations.
      • Export Request -- Start the certificate revocation process by selecting the certificate that you want to revoke. Provide the required configuration properties. Export this transaction as part of an update set, which is imported into the protected instance for approval and execution.
      • Import Request -- Import the update set into the protected instance to initiate the certificate revocation process. Approvers receive email notifications and they should complete the approval workflow before the certificate is revoked. The approval means that the revocations are confirmed, authorized, and traceable for security and compliance purposes.
      • Approve Request -- Review and approve certificate revocation requests from the email approval notifications that are sent to your registered email address. Review the approval notification and select the Click here to approve or Click here to reject link to access the protected instance and act. You can also access the approval request and the code-signing quorum request directly from the email.
    • Disable Code Signing -- Disable code signing on your protected instance.
    • Load Key Pairs and Certificates -- Establish the relationship in a designated trusted instance using Code Signing. This first step loads two cryptographic keys into the trusted environment to establish a trusted source for updates to the production instance.
    • Circle of Trust -- Create an update set in the trusted environment to export the trusted certificate to the production environment.
    • Manage Circle of Trust -- Retrieve the update set in production to establish the trust relationship between the two instances. The certificates that have been created to represent trust in the trusted instance must be accepted into the protected instance.
    • Turn on Code Signing -- Turn on Code Signing in your trusted non-production instance to identify the trusted instances linking to your production instance.
    • Create Key Pairs and Certificates -- Create two key pairs to signed certificates to establish trust between your protected and trusted instances.
    • Custom Firewall Rules -- Configure the External Communication Channel (ECC) firewall in your MID Server by specifying the custom rules to selectively allow or reject the incoming message and override the Code Signing configuration.
    • Root of Trust Settings -- Trust and use your own certificates instead of relying on ServiceNow build certificates (default) by changing to use your Root of Trust (ROT). ServiceNow components like script includes, business rules, etc., are signed at build time using a ServiceNow build time key (verification certificate is the ServiceNow build certificate).
      • Migrate Signatures -- Run a signing job to migrate your signatures to a customer Root of Trust (ROT).
      • Disable Root of Trust -- Run a scheduled job on your trusted instance to disable Root of Trust.
    • Using Code Signing -- Learn how to sign records, messages, and attachments to help verify the authenticity and integrity of your data.
    • Standalone Signing Tool -- Use the standalone Signing Tool to sign supported records in ServiceNow applications using your own private key.
      • Use Signing Tool -- Learn how to use the Signing Tool to sign supported records in ServiceNow applications.
      • Tool Arguments -- Learn about the available arguments for the Signing Tool.
    • JDBC Signing -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
      • Sign Existing Sources -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
      • Sign New Sources -- Use update sets to sign and validate the JDBC data sources by enabling the code signing in protected and trusted instances.
    • REST and SOAP Signing -- Use update sets to sign and validate the REST and SOAP messages by enabling the code signing in protected and trusted instances.
      • Sign the Existing Messages -- Sign and validate the existing REST and SOAP messages by enabling the Code Signing in protected and trusted instances.
      • Sign the New Messages -- Sign and validate the new REST and SOAP messages from the trusted instance by enabling the Code Signing in protected and trusted instances.
    • Sign Records and Files -- Create a security job to sign specific records or attachments rather than all records or attachments on a table.
    • Sign Flows and Actions -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
      • Sign Existing Flows -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
      • Sign New Flows -- Use update sets to sign and validate the flows, subflows, and actions by enabling the Code Signing in protected and trusted instances.
    • Signature Verification -- Signature verification helps confirm that records, scripts, and other signed content originate from trusted sources and remain unaltered.
    • Health and Status Dashboard -- The Code Signing Health and Status dashboard provides a centralized, user-friendly view of your Code Signing environment's health and configuration. Use it to identify issues, verify configuration accuracy, and support secure, uninterrupted code-signing operations.
    • Dashboard Summary -- The Overview dashboard provides a centralized view of your Code Signing environment, offering real-time insights into key components and their status.
    • Signature Status -- View the status of valid, invalid, and missing signatures across different applications to assess code signing coverage. Use this information to identify areas that may require additional attention or action.
    • MID Server Configuration -- Manage and configure the trust relationships and certificate settings for MID Servers.
    • Key Pair and Certificates -- The Key Pair and Certificates dashboard displays details about the cryptographic keys and digital certificates used for Code Signing. It includes information such as key type, certificate issuer, expiration date, and validity status. Use this dashboard to manage code signing certificate credentials, verify their validity, and help ensure secure and trusted Code Signing operations.
    • Configuration Dashboard -- The Code Signing Configuration dashboard displays the system properties and key settings that control Code Signing in your environment, including flags and enforcement policies. These settings enable features, enforce signature validation, and define trusted sources.
    • Utilities Dashboard -- The Utilities dashboard provides a unified workspace to monitor signature status, detect configuration issues and maintain the overall health of your Code Signing environment. It consolidates common Code Signing administrative tasks into a single interface, eliminating the need to navigate across multiple areas of the instance.
      • Batch Signature Generator -- Automatically generate batch update sets for records with invalid or missing signatures on the trusted instance.
    • Administer and Troubleshoot -- Reference topics provide additional information to administer and troubleshoot Code Signing.
    • Properties -- Code Signing adds the following properties.
    • Roles -- Code Signing includes the following roles.
      • Admin -- Code Signing includes the following roles.
      • Manager -- Code Signing includes the following roles.
      • Auditor -- Code Signing includes the following roles.
    • Actions and roles -- Reference table of Code Signing actions, their descriptions, and the roles required to perform them.
    • Logs and Errors -- Access various logs to troubleshoot and identify the failure reasons.
  • Antivirus Scanning -- Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories.
  • Exploring Antivirus Scanning -- Use Antivirus Scanning to help protect your instance against virus infections that can be introduced by file attachments to your system records, such as incidents, problems, and stories.
  • Configuring Antivirus Scanning -- Configure Antivirus Scanning across your instance and at the table level.
  • Reviewing quarantined files -- Review quarantined file attachments and take further action as needed.
    • Review antivirus activity -- Review the Antivirus Activities log that tracks all activities that occur on potentially-infected files from the point that they are discovered and placed into quarantine.
  • Understanding Dictionary attributes -- Dictionary attributes alter the behavior of the table or element that the dictionary record describes. As an administrator, you can set the values of dictionary attributes to modify the behavior of the default Antivirus Scanning configuration.
  • HTML sanitizer -- Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields.
  • Exploring HTML sanitizer -- Remove unwanted code and protect against security concerns such as cross-site scripting attacks by sanitizing HTML markup in HTML fields and translated HTML fields.
  • Configuring HTML sanitizer -- You must modify a script include to make configuration changes to the HTML sanitizer.
  • Enabling HTML sanitizer -- The HTML sanitizer provides a property to enable or disable the sanitizer for all HTML fields in the system.
  • Auditing -- Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others.
  • Exploring Auditing -- Track record changes on auditing-enabled tables. By default, the system tracks changes to the incident, change, and problem tables, among others.
  • Configuring auditing for a table -- You can enable table auditing to track changes to all or some of the table's fields.
    • Enable inclusion list auditing for a table -- Enable a table to audit only those fields you explicitly designate. This is useful when you want to audit only a small number of fields in an audited table.
    • Enable impersonation tracking in audit logs -- Track users who perform actions through impersonation in audit logs.
    • Exclude a field from being audited (exclusion listing) -- Prevent the ServiceNow AI Platform from tracking a subset of fields in an audited table by excluding those fields from an audit.
    • Include a table field in auditing (inclusion listing) -- Track a subset of fields in an audited table by add those fields to an inclusion listing.
    • Enable auditing for a system table -- Deletions from tables with a sys_ prefix are not audited by default. To track deletions from these tables, add the table name to the glide.ui.audit_deleted_tables property. Enabling the Restore Deleted Records plugin adds several default values to this property.
    • Audit Management Console -- Use Audit Management Console module to experience a more enhanced way of defining and configuring the audit capability within your instance.
    • Setup your audit retention -- Use the Retention option to automate and simplify the deletion of audit data as per your requirement.
    • Enable an audit deletion estimate -- Enable the audit deletion estimation feature that calculates the approximate number of records that will be deleted based on retention policies. This information helps you make an informed decision before applying a retention policy, which permanently deletes audit data and cannot be reversed.
  • Viewing Sys Audit and Audit Relationship Change tables -- The ServiceNow AI Platform tracks inserts and updates to audited records in the Sys Audit (sys_audit) and Audit Relationship Change (sys_audit_relation) tables.
  • Knowing about History sets -- The system automatically generates History Set records as needed from the Audit table when a user either creates a record or views its history.
    • Differences Between Audit and History Sets -- The Audit [sys_audit], History Sets [sys_history_set], and History [sys_history_line] tables store the same data, but they serve different purposes and manage data differently.
    • Control access to history -- You can give a role access to view audit history by setting a system property.
    • Change the number of history entries -- By default, the history displays a maximum of 250 history entries, but you can change this value.
    • History List -- The history list displays each change as its own row in the change list.
    • History Calendar -- The history calendar shows you the days where the record was changed, who made the change, and when.
    • History Timeline -- You can view a timeline of changes for a CI and for its related records, relationships, baselines, and proposed changes for the CI. Timelines are available for CIs in the Configuration Item [cmdb_ci] table or a descendant of this table, if auditing is enabled for the tables.
    • View timeline of changes to related records -- On the time line of changes for a CI record, you can also view a timeline of changes for the CI's related records.
    • Export a snapshot of a configuration item -- You can export a snapshot of a configuration item from its timeline.
    • Compare CI snapshots -- You can compare the properties and relationships of a CI at two different points in its timeline.
    • Tracking changes to reference fields -- Administrators can track changes to reference field display values.
    • Tracking inserts -- By default, the system does not create Audit records for inserts because in a typical instance, inserts can account for over 80% of the size of the Audit table.
    • Tracking CI Relationships -- Changes to a CI relationship (CI Relations, CI/User Relations, or CI/Group Relations) appear in the history of the items on both sides of the changed relationship regardless of whether the change was manual or a result of Discovery.
  • Granular admin roles for Audit tables -- Granular admin roles replace broad admin access with targeted, feature-specific permissions. Use these roles to grant the administrative capabilities needed for specific tasks without assigning the admin role.
  • High Security Settings -- High Security Settings refer to several security options available in your instance.
  • Exploring High Security Settings -- High Security Settings refer to several security options available in your instance.
  • Activating High Security Settings -- The High Security Settings plugin is active by default on all new instances. If it is not active on your instance, you can request the plugin.
  • Virtual Private Network (VPN) -- Use a virtual private network (VPN) to integrate your instance with external data sources over the Internet.
  • Exploring Virtual Private Network (VPN) -- Use a virtual private network (VPN) to integrate your instance with external data sources over the Internet.
  • Activating a VPN service -- For all VPN requests, including provisioning, modifications, or general questions, use the Service Catalog VPN Request form.
  • Configuring an address for VPN communication -- To prevent conflict or overlap with internal ServiceNow networks or with another customer's internal IP address schemes, the instance requires that all tunneled traffic in the encryption domain use non-RFC-1918 addresses on both sides of the tunnel.
  • Platform Privacy -- Privacy enables you to mask the sensitive date on the instance.
  • Exploring Data Privacy -- Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.
  • Data Privacy -- Use Data Privacy to classify sensitive data and to remove personally identifiable information (PII) from user data in a production instance and anonymize data in non-production instances. Once anonymized, the user data is no longer considered regulated private information.
    • Data Privacy for Now Assist -- Set up and configure how to discover and anonymize sensitive data from generative AI prompts.
    • Exploring Data Privacy for Now Assist -- Learn more how Data Privacy for Now Assist enhances your ability to protect sensitive data.
    • Configuring Data Privacy for Now Assist -- Configure a data privacy advanced configuration to de-identify personally identifiable information (PII) in generative AI applications.
    • Data privacy (Classic) -- Data privacy (Classic) is available as a family release. The last family updates were released in the Tokyo launch.
    • Activate data privacy (Classic) -- You can activate the data privacy plugin (com.glide.data_privacy) for Platform Security if you have the admin role. If the application doesn't include demo data or it doesn't install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they aren't already installed.
    • Installed with data privacy (Classic) -- Learn about the components installed with the data privacy plugin (com.glide.data_privacy).
    • Data privacy (Classic) configuration -- Learn how to create data privacy techniques and policies, and how to create and execute data privacy jobs.
      • Create a data privacy technique configuration -- Create a data privacy technique configuration to customize how data privacy anonymizes your data.
      • Create a data privacy policy -- Configure a data privacy policy to specify which data privacy techniques are used when anonymizing your data.
      • Configure a data privacy job -- Configure a data privacy job on your production instance to use anonymized data on your non-production instance for user and data class jobs.
      • Data privacy job rollback -- Database changes are captured for actions like jobs and scripts so that the changes can be rolled back. Roll back a data privacy job for when human error inadvertently anonymizes incorrect user information. The rollback de-anonymizes the data from the data privacy job.
      • Roll back a data privacy job -- Roll back a data privacy job on your non-production instance that uses anonymized data from your production instance to a state prior to de-identification of a data class or user job.
    • Data privacy clone -- As customer data are cloned from a source to a target instance, typically from production to non-production, sensitive data are de-identified on the target instance.​
      • Configure data privacy clone request -- Data privacy clone integration is configured using a PostClone script to create and execute data privacy jobs for configured policies on the target. After running the script, users will see de-identified data and will not have access to the original data.
    • Data Privacy Job Logs -- Review errors from Data Privacy jobs.
    • Data Privacy for Virtual Agent -- You can use Data Privacy to detect and mask the sensitive data and PII during a Virtual Agent conversation.
    • Data privacy -- The data privacy store app is a Next Experience refresh for data classification and data privacy with modern look, feel, and usability. Data privacy store app is supported in Utah and above.
    • Data privacy overview -- The Overview homepage is a starting point to manage your data and data privacy compliance.
    • Data classification -- Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.
      • Create data classifications -- Create your own user-defined data classifications in the [data_classification] table that you can then assign to specific columns in specific tables. Create new data classes to start the classification process.
      • Classify data -- Group data by type, using pre-defined or user-defined data classifications. Assign data classifications to specific table columns in the Dictionary [sys_dictionary] table. When you assign data classifications, it creates entries in the Dictionary-Data Class [m2m_dictionary_dataclass] table, which you can then review in the Overview dashboard.
    • Data anonymization -- Anonymization provides a way to easily transform data so that it is unidentifiable and more compliant with data privacy regulations.
      • Create anonymization techniques -- Create a data privacy technique configuration to customize how data privacy anonymizes your data.
      • Create anonymization policies -- Configure an anonymization policy to specify which techniques are used when anonymizing your data.
      • Assign data anonymization techniques -- Assign anonymization techniques for data tables or columns, user specific data, or real time data.
      • Configure data anonymization clone request -- Data privacy clone integration is configured using a PostClone script to create and execute data privacy jobs for configured policies on the target. After running the script, users will see de-identified data and will not have access to the original data.
      • Create anonymization job -- Configure a data privacy job on your production instance to use anonymized data on your non-production instance for user and data class jobs.
      • Activate parallel jobs -- Use parallel jobs to reduce your anonymization job execution time.
      • Anonymization of encrypted columns -- When creating data privacy policies, you may include columns that are also protected by Column Level Encryption (CLE). How you handle those columns depends on your organization's compliance requirements.
    • Real time anonymization -- Use the real time anonymization(RTA) policy to anonymize data entries in real time.
    • Real time protection -- Analyze user input in real time at the field level to identify sensitive data and alert users about potential sensitive data entry.
      • Real time protection policies -- You can configure policies to protect sensitive data in real-time through alerts and blocking actions.
      • User sensitive data logs -- You can view the top 100 activity logs for specific real-time protection policies that contain the most sensitive data from the last month.
      • Alert data patterns -- Before you can define real-time protection policies, you must create your alert data patterns; reusable groups of data patterns that detect and then alert or block sensitive data across your organization.
      • Attachment quarantine policies -- Manage policies that automatically isolate suspicious attachments for security review and analysis.
      • Attachment scan findings -- You can review the findings of your attachment quarantine scans, and work with any quarantined or alerted attachments.
    • Activate data privacy -- Data Privacy includes data classification and anonymization and is installed from the ServiceNow Store.
    • Domain separation -- If any conrefs are broken, re-add them from the doc/source/reuse/domain-separation/domain-separation-overview.dita file. In the short description, edit the first sentence to state whether domain separation is supported or not and add the application name. Keep the conref at the end that describes domain separation.Domain separation is unsupported for data privacy. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
    • Supported field types for anonymization -- Check which field types are supported when anonymizing data.
    • Data privacy roles -- Data privacy adds these roles.
    • Data privacy administrator -- Data privacy adds these roles.
    • Data privacy auditor -- Data privacy adds these roles.
    • Data privacy clone processor -- Data privacy adds these roles.
    • Data privacy processor -- Data privacy adds these roles.
  • Data Discovery -- Use Data Discovery to identify sensitive data within an instance, such as credit card information, emails, or social security numbers.
  • Data Classification -- Group data by type, using pre-defined or user-defined data classifications. If you have an assigned data classification administrator or auditor role, you can administer different data classes or visually analyze the current state of different types of data within the instance.
    • Exploring Data Classification -- Explore about data classification.
    • Installing plugin demo data -- When you upgrade to or install Australia (and above), the Data Classification (com.glide.data_classification) plugin is automatically activated. However, you should manually install the demo data that comes with the plugin. It includes several important pre-defined data classifications, and it also assigns one of them to specific User [sys_user] table columns in your instance.
    • Components installed with Data Classification demo data -- When you upgrade to or install Australia (and above), the Data Classification (com.glide.data_classification) plugin is automatically activated. However, you should manually install the demo data that comes with the plugin. It includes several important pre-defined data classifications, and it also assigns one of them to specific User [sys_user] table columns in your instance.
    • Creating data classifications -- Create your own user-defined data classifications in the Data Classification [data_classification] table that you can then assign to specific columns in specific tables.
    • Assigning data classifications to dictionary entries -- Assign data classifications to specific table columns in the Dictionary [sys_dictionary] table. When you assign data classifications, it creates entries in the Dictionary-Data Class [m2m_dictionary_dataclass] table, which you can then review in the Overview dashboard.
    • Analyzing data classifications -- The Overview dashboard reports the current state of data classifications within your instance and how your users are distributed by location.
    • Domain separation -- Domain separation is supported for Data Classification . Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
  • Encryption -- Protect your sensitive data and stay compliant with regulatory  requirements and standards.
  • Key Management Framework -- Use the Key Management Framework (KMF) to generate, exchange, store, use, and replace the cryptographic keys used to encrypt and decrypt sensitive data on your ServiceNow instance.
    • Exploring the Key Management Framework -- Learn about the components of the Key Management Framework (KMF), and how to use them to manage how cryptographic operations are performed on your instance.
    • Cryptographic module overview -- The Key Management Framework (KMF) is centered around managing Cryptographic modules. Use these modules to select a cryptographic mechanism and define where they're applied on your instance.
    • Cryptographic specification overview -- The Cryptographic specification is the component that defines aspects of your cryptographic module, including its cryptographic purpose and which encryption algorithm to use.
    • Module access policy overview -- Module access policies (MAPs) are access controls that you apply to your cryptographic modules. Use these access policies to decide which users and scripts can access data encrypted by a cryptographic module.
    • Instance level keys in the Key Management Framework -- Learn about the Key Management Framework (KMF) key structure, which uses envelope encryption to ensure that all platform keys under KMF management are protected through a chain of keys. Customer Data Encryption Keys (CDEKs) created by KMF are also included in this structure
    • Configuring the Key Management Framework -- Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.
    • Assign Key Management Framework roles -- Administrators with the security_admin role can assign Key Management Framework (KMF) admins, who in turn can assign other Key Management Framework roles.
    • Configure field encryption settings to select key type -- Configure your field encryption settings to use ServiceNow supplied keys or your own customer-supplied keys (CSK) for encryption on the ServiceNow AI Platform.
    • Create a cryptographic module -- Create a cryptographic module to define the mechanisms used for cryptographic operations. After you create the module, you create a cryptographic specification, where you define an algorithm for encryption and generates a key.
    • Create a module access policy -- Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.
    • Create a cryptographic module life-cycle policy -- Create a cryptographic module life-cycle policy to place limits on cryptographic modules, such as how long the key is good for. Create policies to safeguard cryptographic modules by limiting their exposure.
    • Key Management Framework Reference -- The Key Management Framework (KMF) API/UX lets you fully customize and manage how cryptographic operations are performed on your ServiceNow instance. The ServiceNow Key Management Framework provides a secure and comprehensive interface for instance-side cryptographic key management services.
    • Key Management Framework key life-cycle states -- KMF supports several cryptographic key life-cycle states through the enforcement of specific allowable actions. For example, only keys that are in the active state can be used fully for their intended cryptographic purpose. The following table provides further detail on the varying key life-cycle states.
    • Roles installed with Key Management Framework -- The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.
    • Module access policy visualization -- Use module access policy visualization to view all relevant cryptographic module information on a single UI page.
    • Module access policy debugger -- Use the module access policy debugger to review logging information and understand why your users are or aren’t granted access to an encryption context.
    • Encryption and Key Management subscription bundle -- With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.
    • Key management actions -- One of the core features of KMF is to provide the capability  to manage  keys, such as revoking or rotating keys.  KMF properly secures sensitive data with the most up-to-date encryption materials and life cycle operations.
    • View and manage keys -- Review the status of any key to determine further key action, such as when to renew, rotate, suspend, deactivate, or destroy a current key.
    • Rotate keys -- For increased security, you can rotate your cryptographic keys on a pre-determined schedule. Key rotation is when you retire an encryption key and replace that old key by generating a new cryptographic key.
    • Import a key from a web service -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
    • Import the wrapping / unwrapping key pair -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
    • Import a wrapped key from a web service -- Securely upload an external customer key onto your instance using import a key from a web service (for example the key REST API). Both symmetric and asymmetric public keys can be imported into a targeted KMF cryptographic module.
    • Key Management Framework Health -- Access on-demand health status information for the Key Management Framework. Warning and malfunction errors contain a detailed message.
    • Prepare your instance for GlideEncrypter deprecation -- Use an instance scan script to find and remove GlideEncrypter API calls on your instance. Removing these calls is a necessary step in deprecating 3DES encryption on your instance.
    • GlideEncrypter deprecation -- Learn how to remove the use legacy GlideEncrypter calls from the scripts on your instance.
    • Deprecate GlideEncrypter usage of 3DES for password2 fields -- Deprecate GlideEncrypter usage of 3DES encryption standard on your instance ensure that your instance uses the more secure Advanced Encryption Standard (AES) exclusively for the encryption and decryption of your Password2 data.
    • Key Management Framework Resource Exchange -- ServiceNow Resource Exchange is a KMF feature that gives you the capability to exchange resources between instances in a secure manner.
    • Key Management Framework Key Exchange -- KMF Key Exchange is a subset function of KMF Resource Exchange. Key Exchange securely transfers encrypted data across multiple instances.
    • Configure Key Exchange -- Key Management Framework (KMF) generates automatic key exchange requests for supported cryptographic modules during the fresh installation or upgrade of the instance, and manages the data encryption key locally for the instance.
    • Rekey ciphertext with Key Exchange -- Resource Exchange supports rekeying of ciphertext on the target instance that was encrypted with keys from the source. Rekey activity is tracked in the key life-cycle.
    • Recurring Key Exchange walkthrough -- Use this walkthrough to set up a recurring key exchange in your instance using and Resource Exchange.
    • Infrastructure Security -- Use Infrastructure security tools to create, upload, and manage certificates your instance uses to encrypt traffic from client to server.
    • Generate a Certificate Signing Request -- Use the Generate Certificate Signing (CSR) page to create a certificate signing request to support customer-signed certificates for your instance load balancer.
    • Password2 encryption with the Key Management Framework (KMF) -- Supported by the Key Management Framework, use the Password2 (2-way encrypted) field type to encrypt and decrypt custom fields with segregation of duties, key protection, and life-cycle management. It works in accordance with NIST 800-57 guidelines and provides FIPS 140-2-L3 protection.
    • FlowKMFEncrypter API -- The FlowKMFEncrypter API provides secure encryption and decryption for ServiceNow Flow Actions, using the Key Management Framework (KMF) crypto operations.
    • FlowKMFEncrypter in a Flow Action -- Resolve the "undefined is not a function" error that occurs when a Flow Action calls the FlowKMFEncrypter API, by allowing the operation in the Restricted Caller Access Privilege record.
  • Certificates -- Your instance requires certificates to establish secure connections and validate signatures.
  • Field Encryption -- Protect encrypted data on your instance from unauthorized users, scripts, or system processes using Field Encryption.
  • Column Level Encryption -- Column Level Encryption permits and denies access to encrypted data based on user role. Column Level Encryption includes basic key management using encryption modules.
  • Cloud Encryption with Key Management -- ServiceNow Cloud Encryption offers encrypted storage for the database using block encryption, along with enhanced key management. Cloud Encryption is available with the ServiceNow Platform Encryption subscription bundle.
    • Key management operations -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Rotate a ServiceNow managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Prepare your customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Switch between ServiceNow and customer-managed keys -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Rotate a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Switch to a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Switch to a ServiceNow managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Schedule key rotation -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Withdraw a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Resupply a customer managed key -- The Key Management Operations submodule provides access to view and manage all encryption keys used with ServiceNow Cloud Encryption.
    • Quorum Control Policy -- The Quorum Control Policy specifies the minimum number of approvals required among the total number of selected approvers to reach quorum for customer managed key withdrawal.
    • Configure Quorum Control Policy Settings -- Follow these steps to configure Quorum Control Policy Settings.
    • Manage Quorum Control -- After a withdrawal operation workflow is triggered, quorum actions can be managed from the Key Management Operations page. The key withdrawal operation is blocked until the quorum is met.
      • Approve or deny a quorum control request -- Approve or deny a quorum control request from Key Management Transactions.
      • Approve or deny a quorum request -- When a quorum request has been created, the minimum number of approvals is required by the members. After a withdrawal operation workflow is triggered, quorum actions can be managed using several methods. The users can grant approvals from the Key Management Operations page, My Approvals in the Instance, or directly from the request email. The key withdrawal operation is blocked until the quorum is met.
    • Key management transactions -- The Key Management Transactions submodule displays all transactions that have occurred for the keys in your ServiceNow instance.
    • Cloud Encryption logging -- Learn about logging options for Cloud Encryption.
    • Tamper Detection -- Use tamper detection to improve security by detecting unauthorized changes to your quorum control settings.
  • Full disk encryption -- Full disk encryption (FDE) applies encryption to the entire storage system within the database server only, because this is the only customer data-storing component. FDE protects only against physical loss or theft of storage devices. When encrypted disk servers are powered on and providing data, the encryption provides no additional protection.
  • Edge Encryption -- ServiceNow Edge Encryption encrypts sensitive data on your company premises before sending it over the Internet to your ServiceNow instance (encrypted in flight), where it remains encrypted at rest.
    • Exploring Edge Encryption -- Edge Encryption is a network encryption system that resides on your network and that encrypts and decrypts sensitive data as it travels between your data center and the ServiceNow cloud.
    • Edge Encryption components -- Edge Encryption is composed of the Edge Encryption proxy server that runs on a server in your network, and the Edge Encryption plugin that must be installed on your ServiceNow instance. If using order-preserving encryption types or encryption patterns, a proxy database must also be installed in your network.
    • Edge Encryption clients -- Edge Encryption uses three clients to inform the instance that the proxy is running, to synchronize requests between the proxy and the instance, and to forward all end user requests to the instance after any potential encryption.
    • Key management for Edge Encryption -- You are responsible for providing and managing the encryption keys used by Edge Encryption.
      • SafeNet key versioning -- Use SafeNet key versioning to simplify changing keys. Instead of creating an alias for every new key, SafeNet key versioning keeps the same alias and increments the version.
    • Encryption configurations and patterns -- With Edge Encryption, you can encrypt fields and tokenize strings.
    • Installed with Edge Encryption -- Edge Encryption installs tables to store encryption-related data, system properties to configure default behavior, and the edge_encryption role to administer Edge Encryption.
    • Planning for Edge Encryption -- Successful implementation of Edge Encryption requires planning and preparation.
    • System requirements -- You can run the Edge Encryption proxy application on servers or virtual machines that run on Microsoft Windows or Linux operating systems. For optimum performance, ensure that your configuration meets these requirements.
    • Sizing your environment -- Choosing the number of proxy servers for your environment is an important task. Consider the number of users, redundancy needs, and acceptable latency.
    • Calculate the order-preserving and tokenization database size -- If using order-preserving encryption or encryption patterns, determine the size of your MySQL database by multiplying the number of potential records by record size.
    • Edge Encryption limitations -- Edge Encryption impacts system functions. Carefully evaluate the impact of encrypting a field.
    • Installing Edge Encryption -- You can install an Edge Encryption proxy manually or using the Edge Encryption interactive installer.
    • Request Edge Encryption -- The Edge Encryption plugin (com.glide.edgeencryption) is available as a separate subscription.
    • Set up an Edge Encryption user account -- The Edge Encryption proxies connect to the instance as a user to obtain and update encryption configuration information. Create a user account for this purpose and give the edge_encryption role to the user.
    • Download the Edge Encryption proxy server -- Download the Edge Encryption proxy server application from your instance, and then copy the file to each computer that is to run the Edge Encryption proxy server.
    • Install the Edge Encryption proxy server using the interactive installer -- Install the Edge Encryption proxy server on a Windows or Linux computer using the interactive installer.
    • Install the Edge Encryption proxy server using the command line installer -- Manually install multiple Edge Encryption proxy servers in your network.
    • Authenticate a proxy server -- Specify that a proxy server is a trusted source so that Edge Encryption can process requests coming from that proxy server.
    • Stop the proxy -- You can stop an Edge Encryption proxy from the command line.
    • Uninstall the proxy on Linux -- You can uninstall the Edge Encryption proxy. If you are upgrading the proxy, it is not necessary to shut down and uninstall the current version.
    • Uninstall the proxy on Windows -- You can uninstall the Edge Encryption proxy. If you are upgrading the proxy, it is not necessary to shut down and uninstall the current version.
    • Set up multiple provider SSO -- Set up multiple provider SSO to enable logging in through the Edge Encryption proxy server URL or the instance URL. If you are implementing multiple provider single sign-on (SSO) with Edge Encryption enabled, some users might need to log in to your instance through the Edge Encryption proxy server, while other users might not.
    • Edge Encryption proxy server properties -- The edgeencryption.properties configuration file located in the /conf/ folder contains properties used to configure your environment.
    • CyberArk integration with the Edge proxy server -- Use CyberArk to store passwords in a centralized and secure digital vault to secure passwords that were previously stored in clear text and secured by file access, or that were previously encrypted via a second file.
    • Using a load balancer with the Edge proxy server -- You can use a load balancer to balance the load across the proxy servers in your Edge Encryption proxy setup. If the load balancer and proxy servers are using different ports, specify the host name and HTTPS port of the load balancer to enable users to view responses on their browser.
      • Configure the load balancer -- You can use a load balancer to balance the load across the proxy servers in your Edge Encryption proxy setup. If the load balancer and proxy servers are using different ports, specify the host name and HTTPS port of the load balancer to enable users to view responses on their browser.
    • Upgrading Edge Encryption -- Both instance upgrades and proxy server upgrades require special consideration in an Edge Encryption environment.
    • Schedule proxy server upgrade -- Create an upgrade schedule to enable the instance to upgrade an out-of-date proxy server.
    • Manually upgrade a proxy server running on Linux -- Update a proxy running on Linux.
    • Manually upgrade a proxy server running on Windows -- Update a proxy running on Windows.
    • Roll back a proxy server upgrade -- If a proxy upgrade is unsuccessful, you can go back to the earlier version.
    • Configuring Edge Encryption -- After the Edge Encryption proxy server is installed and running, manage Edge Encryption through the proxy server.
    • Rotate encryption keys -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
      • Schedule a single key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
      • Schedule a mass key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
      • Schedule an attachment key rotation job -- Perform encryption key rotation from the instance. Add a new key, change the default key assignment, and then schedule a mass key rotation or a single key rotation.
    • Encrypt fields using encryption configurations -- Encrypt fields by creating encryption configurations.
    • Encrypt attachments using standard encryption -- You can encrypt attachments for specific tables.
    • Change a field or attachment's encryption type -- You can change a field or attachment's encryption type by selecting a new encryption type in the existing encryption configuration record. A specific table and field combination can only have one active configuration at a time.
    • Tokenize strings using encryption patterns -- You can replace string patterns with tokens before they are sent to and stored in the instance.
    • Repair or recover order-preserving encrypted data -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
      • Schedule an order token repair job -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
      • Schedule a proxy-database recovery job -- If you have the security-admin role, you can schedule jobs performed by the Edge Encryption proxy to repair or recover fields that use order preserving encryption.
    • Configure the IP address deny list -- Prevent an IP address in your network from sending requests to your instance
    • Encrypt data from a record producer -- Configure your Edge Encryption proxy server to allow inserts from a record producer by creating encryption rules from the record producer record.
    • Define a custom encryption rule -- It may be necessary to identify and encrypt sensitive information in HTTP requests on the way to your instance. You can write encryption rules to identify, interpret, and encrypt data in such requests, mapping fields in the request to table-field names on your instance.
      • Inspect the client request -- Before creating a custom encryption rule, you must determine the format of the client request entering the Edge Encryption proxy server.
      • Create an encryption rule -- Encryption rules are used by the proxy to find content in HTTP requests that should be encrypted.
      • Encryption rule conditions -- Encryption rule conditions determine if the rule should be executed.
      • Encryption rule actions -- An encryption rule maps fields in a client request to fields in a table on your instance and identifies fields marked for encryption.
      • Encryption rule objects and APIs -- Use encryption rule APIs to parse and encrypt values in requests moving through the Edge Encryption proxy server to the instance.
      • request -- The request object is a global object available in Edge Encryption rule action and condition scripts.
      • POST and URL parameter APIs -- POST and URL parameters can be accessed as properties of the request object using request.postParams and request.urlParams.
      • XML APIs -- XML APIs can be used after calling getAsXmlContent() on either the request object or a ParameterValue property.
      • JSON APIs -- JSON APIs can be used after calling getAsJsonContent() on either the request object or a ParameterValue property.
      • print(String message) -- Prints a message to the wrapper log file: /logs/wrapper_.log.
      • Prohibited keywords -- The Edge Encryption proxy validates encryption rule scripts before saving the rule. Many JavaScript keywords aren’t allowed in encryption rule scripts.
      • Edge Encryption dictionary attributes -- Add dictionary attributes to tables and fields to control how they work with Edge Encryption.
      • Domain separation and Edge Encryption -- Domain separation is supported in limited circumstances with Edge Encryption. Edge Encryption provides the ability to encrypt data from within the customer's environment through the use of specific configurations, rules, and keys defined on the Edge Encryption proxy. The Edge Encryption proxy is not domain aware and cannot support domain-specific settings. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
      • Data integration with Edge Encryption -- To integrate third-party data with an instance using Edge Encryption, you must route the data through the Edge Encryption proxy server using supported integrations. Supported integrations use base system encryption rules that map data in each payload to fields in a table.
        • ODBC driver integration -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
        • Import a self-signed certificate to the ODBC truststore -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
        • Set the ODBC driver properties -- Configure your ODBC driver to query data encrypted by Edge Encryption. The Edge Encryption proxy server encrypts ODBC driver requests to the ServiceNow instance when Edge Encryption is integrated with the ODBC driver.
        • MID Server integration -- Configure the MID Server to route data through an Edge Encryption proxy server.
        • Point the MID Server to the Edge Encryption proxy server -- Configure the MID Server to route data through an Edge Encryption proxy server.
      • Diagnostics and performance -- Monitor Edge Encryption proxy server performance trends and drill into errors generated by the Edge Encryption proxy server.
      • Increase debug logging for the proxy -- Increase the level of logging to interpret the logs and debug issues with the proxy.
      • Database Encryption -- ServiceNow offers database encryption (DBE) and full-disk encryption methods for customers with statutory obligations for data protection which may require at-rest protection for all data.
      • Access Management -- Access Management enables you to have access to ServiceNow instance securely.
      • Zero Trust Access -- Zero Trust Access (ZTA) is a security model that assumes no user or device is trusted by default.
        • Explore ZTA -- Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.
        • Activating ZTA -- Activate the Zero Trust - Policy Based Session Access com.snc.zero_trust_session_access plugin to enable security admins to reduce or limit user access in a session based on IP address, location, Identity Provider attributes, and user attributes using adaptive authentication policies.
        • Configuring Session Access role -- Configure Session Access to reduce user access in a session based on IP, location, Identity Provider attributes, and user attributes using adaptive authentication policies.
        • System properties -- Use system properties to enable and customize Zero Trust Access to meet your security requirements.
        • Session Access Audits -- The Session Access Audits displays the Session Access logs and information related to a user's session.
        • Tutorial: Use ZTA -- Procedure to use Zero Trust Access feature with an end-to-end use case.
        • Configure IDP attribute for Session Access -- Use Identity Provider (IDP) attribute created from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) for removing or restricting user session access to the instance.
        • ZTA for Mobile -- Zero Trust Access (ZTA) is a security model that assumes that no user or device is trusted by default.
        • Continuous Authentication (CA) -- ServiceNow's continuous authentication enables you to reverify and authenticate a user if they access resources that are protected by you.
        • Exploring CA -- ServiceNow's continuous authentication (CA) enables you to re-verify and authenticate a user if they access resources that are protected by you.
          • Policies -- View the different continuous authentication policies that are created.
          • Metrics -- View the different metrics for continuous authentication.
          • System properties -- Use system properties to enable and customize continuous authentication (CA) to meet your zero trust access security requirements.
        • Pre-work for CA -- Ensure to perform the following pre-work before using Continuous Authentication (CA).
        • Activating CA -- For activating the Continuous Authentication feature on your instance, install the Zero Trust - Continuous Authentication (com.snc.zero_trust_continuous_authentication) plugin.
        • Configuring CA -- Configure continuous authentication (CA) policies to re-authenticate the users if there's an attempt to access resources that are protected by you.
          • Tutorial: Configure CA for a Table -- Procedure that describes end to end configuration of continuous authentication policy for a table and the impacts to the users due to the configuration changes.
          • Tutorial: Configure CA for a Data Class -- Procedure that describes end to end configuration of continuous authentication policy for a data class and the impacts to the users due to the configuration changes.
        • High Assurance -- Establish high assurance session for with ServiceNow's continuous authentication.
          • SSO Login -- Establish high assurance session for SSO login using ServiceNow's continuous authentication.
          • Non-SSO login -- Establish high assurance session for non-SSO logins (local or LDAP) using ServiceNow's continuous authentication.
        • Audit logs -- Describes the details about Continuous Authentication (CA) logs. The CA logs displays all the authentication attempts performed by the users.
      • Domain separation for service providers -- With the ServiceNow Platform, service providers (SPs) can provide their customers with faster onboarding, meet compliance, and protect their data using domain separation. You can separate client data, processes, and reports into logical groupings called domains. SPs control who sees and accesses what content.
        • Exploring domain separation -- With domain separation you can separate data, processes, and administrative tasks into logically defined domains.
        • Delegating configuration options to customers -- Domain separation is designed to give ServiceNow service providers (SPs) the ability to configure the services they offer to their customers. It is not designed to enable their customers to administer those services themselves, except in a few areas that this topic details.
        • Domain assignment -- By default, domain separation adds a domain field to tables and their extensions.
        • Visibility domains and Contains domains -- Visibility domains control what a specific user or group of users can see. "Contains" domains control what an entire domain of users can see.
        • Domain scope -- Domain scope defines what users can and cannot access.
        • Concepts for service providers -- These concepts work with the existing ServiceNow platform capabilities to help you solve for common use cases.
          • Global queue v.2 -- The global queue concept provides a single virtual view of tasks that reside in multiple instances. The concept creates a custom application to provide a fulfiller view of work that resides in multiple instances without having to replicate tasks or data.
          • Service provider connector -- The service provider connector application is a reference design for creating a ServiceNow Store application for your customers to use to integrate with your systems. Service provider applications help you speed on-boarding and create standardized integrations.
        • Installed with domain separation -- Several platform components are added or modified with domain separation.
        • Application support for domain separation -- Many ServiceNow applications support domain separation in the base system but not all. Some supported applications include limitations on the data and administrative settings that can be domain-separated. These definitions delineate the domain separation support levels from the perspective of actual use cases and the people who use them.
        • Recommended practices for service providers -- You can create, implement, and maintain domain separation for your applications and services.
        • Domain separation explained -- With domain separation, you can segregate application data, UI, and business logic, such as rules or workflows, in a single customer instance. Separating these elements into logically defined domains supports specific hierarchies for all customers using your applications.
          • Value proposition -- With domain separation, service providers can have a multitenant instance architecture that delivers offerings efficiently and securely to their clients. Strong universal process standards, data-driven process design, strict governance, and centralized administration help to maximize these benefits.
          • Definition of domain separation -- With domain separation (also known as the ServiceNow Multitenant Platform Architecture), you can segregate application data, UI, and business logic in a single customer instance that supports hierarchical modeling with cross-tenant (customer) intelligence.
        • Domain separation hierarchies -- Create a hierarchy when defining a domain architecture to track your processes and workflows.
        • Context and domain separation -- The context of a user's session determines the processes, data, and user interface (UI) as the user browses through list views, home pages, reports, and knowledge articles. The context is determined by the processes that you create, the business rules that you set, your workflows, and other factors.
        • Segregating and securing data -- You can segregate and secure data on the ServiceNow platform in multiple ways, depending on your customer's needs. 
          • Cross tenant intelligence -- A multi-tenant architecture is where you have a single instance serving multiple tenants. Data, metadata, business logic, and processing context for tenants is automatically handled with access to additional tenant data.
        • Alternatives to domain separation -- You can use a separate instance as an alternative to domain separation for your customers. A separate instance allows you the flexibility to meet the requirements for data separation within the groups and departments in an organization with little to no impact on others.
        • Evaluating the need for domain separation -- You may find that domain separation doesn't always work for your customers' organizations. It's best that you base your decision to go with domain separation by looking at your customers' needs.
        • Benefits of domain separation -- Domain separation may work better for your customers' organizations than any other method for separating the data between groups and departments.
        • How a database query works with domain separation -- Using database queries with domain separation in your customers' applications help them protect their data. These queries then speed up the configuration and build processes.
        • Domain separation levels of support -- Choose from three categories for domain separation of an application for your customers' organizations.
        • Service provider reference architecture -- Your customers can access service provider (SP) services by using a portal that is designed for them to reach their domain-separated instance.
          • Decision trees -- You can use decision trees and a comparison chart to determine if a new customer should be added to a shared instance or to their own dedicated instance.
          • Dedicated instances -- Service provider (SP) customers can access SP services by using a portal to a dedicated instance. SPs use these dedicated instances to manage their service delivery.
          • Hybrid solution -- Use the hybrid service provider (SP) reference architecture for a customized solution. Your customers require a dedicated instance for a specific service. They can still use the shared SP instance for other services, but it requires integration of each instance.
          • Service Integration Management (SIAM) -- The Service Integration Management Service Integration and Management (SIAM) for service provider (SP) architecture integrates services for a unified customer experience.
        • Domain separation terms -- With a ServiceNow instance, you can improve efficiency, add greater security, and increase performance for your customer organizations. It's helpful to understand some of the most common terms as you create your configurations.
        • Domain-separate a custom table -- You may need to create custom tables in separate domains. This topic covers both the procedure and the concept behind domain-separating a custom table.
        • Customizing domain properties and themes -- You can customize your customers' company properties and themes within the domains that you have configured. Customization makes their instances fit in with their companies' overall look and feel.
        • Managing domain separation for specific uses -- You can set up separate domains for email notifications and customize the properties of catalog, tables, users, groups, and views. This enables you to provide more specific behavior in each domain, giving your customers more flexibility.
        • Configuring domain separation with the domain picker -- Use the domain picker wisely, and remember the 80/15/5 approach so that you do not customize too much and impact the performance of your instance.
        • Performance considerations -- As you configure domain separation in your application and services, make sure that you consider the number and properties of domains you create. Too many property-heavy domains can impact the performance of your instance.
        • Setting up domain hierarchies -- You can avoid slowdowns and performance impacts in your instance by knowing how domain hierarchies work and by setting them up properly.
        • Checking domain logs for errors and warnings -- Check the domain logs to find errors or warnings in your domain path processes and hierarchy configurations.
        • Importance of the Default domain -- Organizing your domains is a crucial part of the domain separation process. If you don't set a default domain, new tasks and user records go to the global domain. Anyone can see the records in the global domain, which means that data can be seen when it is not supposed to.
        • Contains queries and domain access -- Use a "contains" query only in special cases, such as when users or groups need to see data from a domain that they don't have access to, but you don't want to move those users to a domain. Creating domain "contains" and user or group access for a domain should be an exception, only when absolutely needed.
        • Domain paths query method -- You can create effective queries with domain paths.
        • Slow queries and SQL debugging -- Debugging SQL and slow queries can help you resolve slowness issues in an instance.
        • Before Query business rules -- You can use a Before Query business rule to help support data segregation on an instance. ServiceNow applications that support domain separation may support the separation of data and data routing only, have advanced business logic separation, or support tenant (customer) level administration of the application.
        • Avoiding domain path in scripts -- Domain paths can cause the values of your script to change or even break, so don't use them in scripts.
        • Domain assignments -- How you assign a domain impacts the value of the sys_domain field. The assignments contain designs and business properties that affect how the application functions in each domain.
        • CSM plugin -- For the best outcome, be aware of how the properties in the CSM plugin work. When the plugin is enabled, you can see the status of your records in your domains.
        • Domain Separation Help -- Additional assistance with Domain Separation
        • Setup and administration -- Setting up domain separation involves requesting activation of a plugin, setting options, and assigning users and records to domains.
        • Request domain separation -- All domain support features are activated with a plugin called Domain Support - Domain Extensions Installer. Administrators can request activation of this plugin.
        • Domain separation plugin -- The Domain Support - Domain Extensions Installer plugin activates several domain separation features and properties at once. This plugin is typically referred to as the Domain Separation plugin.
        • Domain system properties and user preferences -- Administrators have access to properties and user preferences that control domain scope.
        • Create a domain -- You can create a domain by creating a record in the [domain] table.
        • Make a domain the default -- Made a domain the default domain to which the system automatically assigns task and user records that are not already assigned to a domain.
        • Manually manage the domain for particular records -- By default, the system automatically assigns a domain based on the user's company record. In some cases, however, domain administrators want to manually manage which domain a particular record belongs to.
        • Domain Separated Tables -- You can see at a glance which tables are domain-separated in your instance with the Domain Separated Tables feature.
        • Domain Override Viewer -- With the Domain Override Viewer, you can see and manage all your process overrides at once across the entire instance.
        • Enable or disable a domain -- When you activate or deactivate a domain, the activation status cascades to companies within the domain.
        • Add a domain field to a table -- As an administrator, domain-separate a custom table by adding a sys_domain field to it.
        • View upgraded processes or records in the global domain -- You can track and review base system records or processes in the global domain that were overridden across one or multiple domains prior to an upgrade and were subsequently updated during a platform or app upgrade.
        • View domain relationships -- The domain map offers domain administrators a read-only representation of the active domains on the instance and how they relate to each other.
          • Select a primary domain -- The primary domain indicates the top-level domain in the domain map.
          • Create Contains relationships between domains -- Create a "contains" relationship between domains to change the domain hierarchy.
          • Expand domain scope -- By default, when a user in the global domain views a table containing a sys_overrides column, the user sees records from only the global domain. When an admin in the global domain views a process table, that admin sees only records that are in that process table.
          • Add domains to a visibility domains list -- Adding a visibility domain allows a user or group to see and potentially edit records from another domain regardless of the user or group's normal domain membership.
          • Grant visibility domains to an individual user -- While it is possible to add visibility domains for specific users on the User form, it's best to add them only via groups. This controls permissions and access should individuals change departments or leave the company.
        • Create a domain-specific choice list -- Administrators can configure choice lists to contain entries specific to a particular domain.
        • Advanced administration -- Administrators can view information about domain separation, identify potential issues, and change configuration settings.
          • Use domain selection menus -- The instance offers domain selection via two menu formats.
          • Enable domain selection menus in Core UI -- Displaying the domain picker in Core UI enables the domain selector by default. After enabling the domain selector, you can add a system property to enable the domain reference picker.
          • Restrict access to the domain picker -- Use a system property to restrict access to the domain picker in Core UI and Next Experience.
          • Application properties -- The Domain Separation plugin has two new tables to give service providers more flexibility in customizing their applications that use domain separation. These tables are the System Application Property table [sys_application_property] and the System Application Property Value table [sys_application_property_value].
        • Domain Migration Tool -- Use the Domain Migration Tool to move a customer from a domain-separated environment to their own dedicated instance.
        • Process administration -- Process administration allows administrators to set domain-specific policies.
        • Enable logging and debug messages -- Domain log and debug messages allow you to troubleshoot domain configuration errors.
        • Post-Production Domain Separation Activation Utility -- The post-production Domain Separation activation utility aids in the activation of Domain Separation in a live environment.
        • Domain Job Management -- Queue multiple Domain Separation updates sequentially into a single background job using the Domain Job Manager.
        • Delete by domain -- Clean up inactive leaf level domains in the domain hierarchy with a controlled and automated tool.
        • Domain Separation Center -- Audit your domains regularly to reveal problems.
        • Configure the Domain Separation Center -- Specify which tables in domains are large and whether you want detailed logging.
        • Configure audits -- Configure whether an audit is active and how frequently it runs.
        • Schedule audits -- Specify the time and day that audits are run.
        • Execute audits immediately -- Audits typically run as scheduled. You can, however, run all audits on command.
        • View audits with warnings and errors -- The Domain Separation Center provides details about audit errors and warnings.
        • View running and pending results -- You can view running and pending audits to see their status.
        • View inactive audits -- You can view all inactive audits in one place and optionally activate them.
      • Security data filters -- Security data filters restrict access to records based on role, or security-attribute related assertions.
        • Create a security data filter -- Learn how to create security data filter rules to grant your users' access to records and tables.
        • Default security filters -- Generally data filters are applied after absolute ACLs (also sometimes called table-level ACLs), and after row-level ACLs. They are applied by default, and can be impactful to system behavior if not used carefully.
      • Authentication -- ServiceNow's authentication validates the identity of a user who accesses an instance, and then authorizes the user to features that match the user's role or job function.
        • Adaptive authentication -- Use the Adaptive authentication policy framework to enforce contextual authentication controls to the right users at the right time. Adaptive authentication uses authentication policies to evaluate authentication requests and then either deny or allow access to your instance based on the specified policy conditions.
        • Activate adaptive authentication -- You can activate the Adaptive Authentication plugin (com.snc.adaptive_authentication) for Adaptive Authentication if you have the admin role.
        • Filter criteria -- Filter criteria (also called policy inputs) are used as inputs for policy conditions to verify and meet the requirements of an authentication request.
          • IP Filter -- Use IP filter criteria to filter the users based on the user's IP addresses. Both IPv4 and IPv6 are supported.
          • Create IP filter criteria -- IP filter criteria allows you to filter users based on the user's IP addresses. You can configure an authentication policy to allow or deny access to a specific address or range of addresses.
          • Role Filter -- Use role filter criteria to filter users based on their roles.
          • Create role filter criteria -- Role filter criteria allows you to filter users based on the roles. You can configure an authentication policy to allow or deny access to a list of user roles.
          • Group Filter -- Use group filter criteria to filter users based on the user group to which the user belongs.
          • Create group filter criteria -- Group filter criteria allows or denies user access based on the user group to which the user belongs.
          • Location Filter -- Location filter criteria can be used as filter input for users based on the user location.
          • Activate Location Based Access -- Activate the Zero Trust - Location Based Access (com.snc.zero_trust_location_access) to allow admins to configure adaptive authentication policies based on the location of the user.
          • Create Location filter criteria -- Use location filter criteria to filter input for users authentication based on the user location.
          • Tutorial: Use Location Filter criteria -- Describes steps to use location filter criteria in the authentication policy and restrict access to the users based on the location.
          • Identity Provider Attributes Filter -- Use the Identity Provider attributes that are received from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
          • Attributes for SAML -- Use the Identity Provider attributes that are received from the Security Assertion Markup Language (SAML) response and OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
            • Use as filter criteria for SAML -- Use the Identity Provider (IDP) attribute from the Security Assertion Markup Language (SAML) response as a filter criteria for authentication policy.
          • Attributes for OIDC -- Use the Identity Provider attributes that are received from the OpenID Connect (OIDC) from the Identity Provider (IdP) as a filter criteria for authentication.
            • Use as filter criteria for OIDC -- Use the Identity Provider (IDP) attribute from the OpenID Connect (OIDC) response as a filter criteria for authentication policy.
        • Authentication policy contexts -- Use authentication policy contexts to determine how and when your instance enforces authentication policies.
          • Pre authentication context -- The pre authentication policy context defines how and when a policy is enforced during the login process. The policy used in this context executes before your users see a login screen.
          • Post-authentication context -- The Post Authentication policy context defines how and when a policy is enforced during the login process. The policy used in this context executes after your users see a login screen.
          • MFA context -- The Multi-factor Authentication (MFA) policy context uses a policy to define how and when MFA is enforced during the login process.
          • Account recovery context -- The account recovery context uses a policy to define how and when the account recovery can be established.
          • Session validation context -- Use the Session Validation Context as an additional layer of protection against session or cookie hijacking.
          • Activate session validation context -- Use session validation context to restrict access to ServiceNow when hijackers copy a user's session cookies from one device to another to impersonate the session or restricts the user's session access if they’re using an insecure network.
          • Tutorial: Configuring session validation -- Configure session validation within the Adaptive Authentication framework to provide as an additional layer of protection for session or cookie hijacking.
        • Authentication policies -- Authentication policies evaluate authentication requests based on the specified policy conditions and either allow or deny access depending on the output of policy conditions evaluation. For example, access is allowed only if all the policy conditions specified in Allow Access Policy evaluate to true.
          • Configure a policy -- Configure an authentication policy to define inputs and conditions to used to grant access to an instance or enforce multi-factor authentication.
          • Add to an authentication policy context -- Add an authentication policy to one of the authentication policy contexts. The authentication context uses the policy inputs and conditions to determine whether uses are granted access to the instance, or whether MFA is enforced for your users.
        • Adaptive authentication events -- You can use the adaptive authentication events table to know about the events.
        • Configure properties -- After activating adaptive authentication, configure adaptive authentication properties according to your security requirements.
        • Adaptive authentication for Trusted Mobile apps -- Access your ServiceNow from untrusted networks by using the Now Mobile app.
        • API Authentication -- Authentication configurations for API.
        • Certificate based authentication -- Certificate-based authentication lets you mutually authenticate inbound API requests using certificates from a trusted Certificate Authority (CA).
        • OAuth -- OAuth based authentication validates the identity of the client that attempts to establish a trust on the system by using an authentication protocol.
        • Token-based authentication -- Token-based authentication for inbound REST APIs configuration using API Key or HMAC.
        • Basic authentication -- Legacy API authentication method using username and password, with restricted usage and varying behaviour in zBoot and upgraded instances.
          • Basic authentication restriction -- Basic authentication restriction is a security feature that controls which accounts can use basic authentication on a ServiceNow instance. Administrators can review identified users and assign per-account decisions before enforcement begins.
          • Basic authentication exceptions -- The Basic Auth Exceptions table lists accounts that have been identified as using basic authentication on the instance, along with their assigned decision and usage details.
        • API access policy -- API access policy defines the permissions and duration of access to an API.
        • REST API access policies -- REST API access policies allow you to restrict access to inbound REST APIs based on the authentication type and the specified filter criteria of the access policy.
          • Activate REST API access policy -- You can activate the REST API Access Policy plugin (com.glide.rest.policy) if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
          • Create an authentication profile -- Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.
          • Create REST API access policy -- Create an API access policy and map an authentication profile to restrict the authentication type for a REST API. For example, you can create an API access policy that allows only ID token authentication for a REST API.
          • API access policy prioritization -- Learn about the policy prioritization logic if there are multiple API access policy configured for your ServiceNow instance.
          • REST API Auth Scope -- Use the REST API Auth Scope to provide access to a specific REST API
          • Activate REST API Auth Scope -- You can activate the REST API Auth Scope plugin (com.glide.rest.auth.scope) to link the OAuth entity with authentication scopes.
          • Properties and tables -- The REST API Auth Scope plugin (com.glide.rest.auth.scope) includes the following system properties, tables, and scripts.
          • Configure auth scope -- Link the OAuth entity with an auth scope to manage the token to access the REST APIs that are linked with the auth scope.
          • Troubleshooting -- Troubleshooting actions can help resolve common issues when setting up or running the REST API scope.
        • SOAP API access policies -- SOAP API access policies allow you to restrict access to inbound SOAP APIs based on the authentication type and the specified filter criteria of the access policy.
          • Activate SOAP API access policy -- For SOAP API access policy, install the SOAP API Access Policy (com.glide.soap.policy) plugin.
          • Create an authentication profile -- Create an authentication profile and add one or more authentication policies to the profile. You can also configure the ID Token and OAuth Token authentication profiles that are available by default.
          • Create SOAP API access policy -- Create an API access policy and map an authentication profile to restrict the authentication type for a SOAP API. For example, you can create an API access policy that allows only ID token authentication for a SOAP API.
          • Create a global API access policy to protect SOAP APIs -- Create a single global API access policy to protect all the SOAP APIs.
          • Filter criteria for APIs -- Filter criteria contains filter conditions or queries that are used as policy inputs for an authentication policy. Policy inputs are used to group one or more filter criteria and define the policy conditions of an authentication policy. For example, an IP Filter Criteria define an IP address in the Classless Inter-Domain Routing (CIDR) format or a range of IP addresses.
        • API Authentication Policies -- Authentication policies evaluate authentication requests based on the specified policy conditions and either allows or denies access depending on the matching criteria.
          • Create a policy -- Authentication policies allow you to enforce access restrictions on the APIs based on the specified filter criteria.
          • Configure global blocking policy for APIs -- Global blocking policy denies the authentication requests of users and APIs based on the specified policy conditions. This policy can be used as an alternative to the IP Address Access Control.
        • System or Export Processors -- Ability for System or Export Processors to leverage processor access policy to secure all the export endpoints.
        • Authentication factors -- Authentication factors help identify and verify callers, allowing only authorized users to access AI voice agents on the ServiceNow AI Platform.
        • Explore authentication factors for AI voice agents -- Authentication factors are the elements used for caller identification and authentication. In secure voice agent environments, the process begins with identifying the caller, followed by authenticating their identity before granting access. A robust security strategy combines multiple factors to confirm that only authorized users interact with AI voice agents.
        • Configure authentication factors for AI voice agents -- To secure voice agent environments, configure authentication factors that first identify the caller, then authenticate them before granting access.
          • Configure voice input for authentication factors -- Configure how callers provide authentication responses by speaking or using the phone keypad.
          • TOTP authentication -- A time based one-time password (TOTP) is a secure authentication factor that verifies user identity by generating a unique, time-sensitive code.
          • Push notification - Okta verify -- The Okta Verify app push notification enables users to securely approve authentication requests directly on their enrolled mobile devices.
          • Configure push notification (Okta Verify) -- Configure Okta Verify to receive push notifications for secure and convenient identity verification.
          • Soft PIN authentication -- Soft PIN is a six-digit numeric PIN that verifies a caller's identity during an AI voice agent session.
          • Configure Soft PIN -- Users are required to configure Soft PIN before it can be used for authentication with ServiceNow AI Platform.
          • SMS OTP authentication -- SMS one-time password (OTP) authentication is a method used to verify user identity by sending a temporary, numeric code to the user's registered mobile number. The user enters this code to complete authentication.
          • Email OTP authentication -- Email OTP for AI voice agents sends a one-time numeric code to the caller's email address. The caller retrieves the code from their email and provides it to the agent to verify their identity.
          • Configure Email OTP -- Configure the Email one-time password (OTP) to enable OTP-based authentication for users in your instance.
          • Knowledge-based authentication -- Knowledge-based authentication (KBA) is an identification and authentication method that verifies callers by prompting them to answer preconfigured questions across conversational AI channels, such as AI voice agents. KBA can be used to identify a caller, authenticate a caller, or both within the same interaction.
          • Configure KBA -- Configure knowledge-based authentication (KBA) to identify and authenticate callers by prompting them to answer preconfigured questions across conversational AI channels, such as AI voice agents.
            • Create KBA questions -- Create knowledge-based questions to use for caller identification and authentication in AI voice agent interactions.
            • Create KBA answers -- Create knowledge-based answers for the preconfigured security questions to confirm the user's identity.
            • Map KBA questions to answers -- Create knowledge-based questions and answer mapping to confirm the user's identity.
            • AI voice agent service mapping with KBA -- Specify the questions used for caller identification and authentication with a specific AI voice agent service.
        • Certificate-based authentication -- Certificate-based authentication lets you mutually authenticate user logins or inbound API requests using certificates from a trusted Certificate Authority (CA).
        • Set up -- Set up mutual authentication for either user interface-based logins or inbound web services.
        • Log in -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
          • Register client certificate for your PIV or CAC card -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
          • Log in to ServiceNow AI Platform using PIV or CAC card -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
          • Manage your client certificates -- After your administrator sets up Certificate-based authentication, you can register the client certificate and log in using your PIV (Personal Identity Verification) or CAC (Common Access Card) card.
        • Custom instance URLs -- You can enable your ServiceNow instance to be accessible from a company-branded or custom URL.
        • Activate custom URLs -- Enable custom URLs to be set up on your ServiceNow instance. You can activate the Custom URL plugin (com.snc.customurl) if you have the admin role.
        • Set as the instance URL -- Add a custom URL to your instance configuration to use instead of your ServiceNow URL.
        • Identity Provider -- Set your custom URL with the Identity Provider to enable the user to login with their IdP's.
        • Datacenter job information -- Every custom URL that is associated to your instance has a corresponding ServiceNow datacenter job which runs and shows URL information that is pertinent to your instance as described in the table.
        • Generate SP metadata for SAML/SSO -- A SAML or SSO installation needs the SP metadata generated for the IdP before the custom URL instance generates.
        • Custom URL errors and fixes -- A list of common errors and associated fixes for a custom URL setup and configuration.Target Audience: ServiceNow Admin
        • Installation exits -- Installation exits are customizations that exit from Java to call a script before returning back to Java.
        • IP range based authentication -- One way to secure a web-based application is to restrict access based on the IP address.
        • IP Address Access Control -- Apply an IP access control to outbound traffic, inbound traffic, or bidirectional traffic. The system only blocks an IP address if a matching Deny rule exists and no matching Allow rule exists. By default, there are no restrictions on access to your instance.
        • Find denied IP addresses -- Find Denied IP addresses in the instance's node log files.
        • LDAP integration -- An LDAP integration allows your instance to use your existing LDAP server as the primary source of user data.
        • Understand LDAP integration -- An LDAP integration allows your instance to use your existing LDAP server as the primary source of user data.
        • LDAP integration requirements -- Review the requirements for LDAP integration, which include a PKI certificate an LDAP compliant directory services server.
        • LDAP integration setup -- Administrators can enable LDAP integration to allow sign-on of users from their company LDAP directory.
        • Import and map data -- LDAP import maps match fields in your LDAP database to fields in your instance.
        • LDAP integration troubleshooting -- If you are integrating your LDAP server and have questions, these items may help you troubleshoot the issue.
          • View the LDAP monitor -- You can view current information about LDAP servers and listeners using LDAP monitor.
          • LDAP error codes -- The LDAP Log file lists industry standard error codes for both LDAP and Active Directory (AD).
          • Send a one-time password when the LDAP server is down -- An LDAP property is available to send a one-time password to a user if the user is unable to log in because the LDAP server is down. You can also configure another property to control how long the password is valid.
        • LDAP record synchronization -- Administrators can synchronize inactive, disabled, or deleted LDAP records with their LDAP records.
          • LDAP refresh filters -- Filters on the LDAP refresh process can be used to specify processing that ignores inserts of disabled users.
          • LDAP extraction -- Implement an LDAP extraction process to detect inactive users.
          • Inactive LDAP user accounts -- Detect that an existing, current, user account is inactive or has been disabled or deleted from an Active Directory (AD) LDAP.
          • Use the userAccountControl field -- Identify when an Active Directory (AD) user is deleted (or made inactive).
          • LDAP script examples -- The following script examples assume you use an Active Directory (AD) for your LDAP server.
        • Active Directory Application Mode (ADAM) -- Active Directory Application Mode (ADAM) is an Lightweight Directory Access Protocol (LDAP)-compliant directory service.
          • Configuring an instance -- The first install copies the ADAM files to your computer, registers requires components, and creates the application shortcuts.
          • Set up the ADAM console -- Set up the ADAM console. Even though there are many similarities between ADAM and Active Directory, the administration can be very different since there is no Users and Computers management console.
          • Create containers and organizational units -- Logically group objects stored in ADAM into containers and organizational units (OU) just as they would be in Active Directory.
          • Delegation with ADAM -- Once the OU structure is created, define the permission delegations to properly secure the objects to limited users.
          • Populating ADAM Objects -- ADAM Objects include User Objects, UserProxy Object, and Group Objects.
          • Testing and troubleshooting -- The primary tool used for testing is LDP. This allows you to fully test user authentication.
          • Backup and recovery -- All ADAM data can be backed up using standard file system backup methods.
          • Use LDAPS with ADAM -- The default configuration for userProxy object authentication is to enforce LDAPS (secure LDAP) communications. LDAPS requires SSL certificates to secure the network traffic.
          • Assign the certificate to ADAM -- Install an SSL certificate on the server and any LDAP client to support secure binds and encrypt the user and password information being transmitted.
          • Export the public key certificate -- LDAPS clients, including the instance need the public key certificate in order to make a secure connection to ADAM.
          • ADAM access account -- The system requires a user account to read the Active Directory Application Mode (ADAM) object information that is imported into the application instance.
          • Test the LDAPS connections -- Test the LDAPS connections. There are two console connections, one for Local Computer Certificates, and the other for Local Computer Services Certificates on the new ADAM service.
          • Use ADAMSync to populate ADAM -- Administrators use MS ADAMSync to populate LDAP directories that use MS ADAM.
          • Define ADAM user accounts -- Define user accounts in ADAM. One user account is used for the instance to connect with and the other user account is for ADAMSync.
          • Set up ADAMSync -- ADAMSync is included with Windows Server 2003 R2. Download and install ADAMSync if you are using a different OS.
          • Install the ADAM configuration file -- Install the ADAM configuration file through the Windows command line.
        • Configure Microsoft AD for secure LDAPS communication -- Use certificate pairs to enable Microsoft Active Directory (AD) LDAPS communications.
        • LDAP global catalog usage -- A DC can be granted the Global Catalog (GC) role. Global Catalog (GC) role is an LDAP-compliant directory consisting of a partial representation of every object from every domain within a forest.
        • OpenLDAP minor schema modification -- In OpenLDAP 2.3 systems that use the back-bdb (Berkley backend), administrators make a minor modification to their schema to facilitate the integration.
          • Modify the schema -- Modify the OpenLDAP schema. These steps detail a schema modification to OpenLDAP 2.3 provided by one of our customers that helped them integrate with their instance.
        • Record LDAP deletions -- By default, the instance does not delete any entries after they disappear from LDAP.
        • Limit concurrent sessions -- You can limit the number of concurrent interactive sessions for a user or role on an instance across all nodes.
        • Explore limit concurrent sessions -- You can limit the number of concurrent interactive sessions for a user or role on an instance across all nodes.
        • Configure the plugin -- You can activate the Limit Concurrent Sessions plugin (com.glide.limit.concurrent.sessions) if you have the admin role.
        • Set a limit by user or role -- You can set a concurrent session limit on a specific user or on a particular role.
        • Disable a limit by user or role -- You can disable a concurrent session limit on a specific user or on a particular role.
        • Local authentication -- Use ServiceNow local authentication to secure the users login on a local device.
        • Login and authentication security -- Configure login security options to control access to your instance.
        • Define login scenarios -- You can direct all users to the same page after login.
          • Employee self-service portal -- The system keeps track of the first starting page that a user is trying to access even if the user wants to log in to the Employee Self-Service Portal.
          • Specify a login landing page -- By default, users see their homepage upon login. You can specify a different login landing page by using a system property or the content management system.
          • Specify lockout for failed login attempts -- The system provides inactive script actions that enable you to specify the number of failed login attempts before a user account is locked and to reset the count after a successful login.
          • Make UI pages public or private -- You can make pages public if you want your users to see the pages without logging in.
        • Password complexity requirements -- Passwords in your ServiceNow instance must meet complexity requirements.
        • Password Reset -- The default self-service Password Reset process enables a user to reset the password without assistance from service desk agents.
          • Modify notification email -- Users of the self-service Password Reset process receive an email notification when they request password reset. You can modify the text of the email and other aspects of the notification.
          • Configure properties -- You can specify properties that configure the Password Reset experience for end users.
        • Remember me -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
          • Change the default value of the Remember me check box -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
          • Remove the Remember me check box -- When the Remember me check box is selected at login, a cookie is stored on the user's computer. This cookie automatically authenticates the user upon subsequent visits.
        • Configure the logout confirmation prompt -- You can enable a logout confirmation prompt to prevent users from inadvertently logging themselves out.
        • Implement a nonce -- You can implement a nonce to be used with single sign-on digest authentication.
          • Nonce process flow -- When a customer has implemented the digested token Single Sign-on and wishes to add the security of a nonce, they follow a certain process flow.
          • Implement a nonce -- Add a cryptographic nonce to the authentication header to ensure that it can only be used once.
        • Multi-factor authentication -- Learn how to activate, use, and configure Multi-factor authentication (MFA).
        • MFA enforcement -- Enforcement of MFA for non-SSO logins to ServiceNow from the Yokohama release.
        • Exploring MFA -- Multi-factor Authentication (MFA) is an authentication method that requires users to provide information other than their basic credentials.
        • Configuring MFA -- Configure multi-factor authentication (MFA) to improve your users security posture when using ServiceNow.
        • Using MFA -- Learn how to use multi-factor authentication tools to securely access your instance.
        • MFA Dashboard -- View the different MFA metrics to understand the MFA adoption and usage.
          • User Metrics -- User Metrics displays the user MFA enrollment trends on ServiceNow.
          • Log in Metrics -- Log in Metrics displays the log in trends on the ServiceNow.
          • MFA Guided Setup -- Use the MFA Guided Setup to step through the initial configuration of the MFA module and understand the requirements for MFA enforcements.
        • Multi-Provider single sign-on (SSO) -- External SSO allows organizations to use several SSO identity providers (IdPs) to manage authentication as well as retain local database (basic) authentication.
        • Activate Multi-Provider SSO -- This integration requires the Integration - Multiple Provider Single Sign-On Installer (com.snc.integration.sso.multi.installer) plugin.
        • Properties, tables, and scripts -- The Integration - Multiple Provider Single Sign-On Installer plugin includes the following system properties, tables, and scripts.
        • Multi-Provider SSO configurations -- You must perform several steps to set up Multi-Provider SSO, including configuring properties, creating identity providers (IdPs), and configuring users to use SSO.
        • OIDC as a SSO identity provider -- OpenID Connect (OIDC) is an identity layer built on top of the OAuth protocol, which provides a modern and intuitive Single Sign-on (SSO) experience to you and your end users.
        • SAML -- The Security Assertion Markup Language (SAML) is an XML-based standard for exchanging authentication and authorization data between security domains.
        • OAuth authentication -- OAuth based authentication validates the identity of the client that attempts to establish a trust on the system by using an authentication protocol.
        • OAuth 2.0 -- OAuth 2.0 lets users access instance resources through external clients by obtaining a token rather than by entering login credentials with each resource request.
          • Set up OAuth -- Set up and activate OAuth, enable the OAuth system property, create an OAuth application endpoint for external client applications to access the instance, and set OAuth parameters.
          • Activate OAuth -- By default, the OAuth 2.0 (com.snc.platform.security.oauth) plugin is active on new and upgraded instances. If the plugin is not active on your instance, you can activate it.
          • Set the OAuth property -- To generate OAuth 2.0 tokens to registered applications, the com.snc.platform.security.oauth.is.active property must be active for the instance.
          • Change OAuth password parameter -- Use this property to ensure only POST body parameters are accepted as input for all supported grant types.
        • OAuth Inbound -- OAuth Inbound authentication allows trusted external applications to securely access ServiceNow APIs, ensuring controlled and authorized connections.
          • Inbound Integrations -- The new inbound integration workflow in the ServiceNow Machine Identity Console provides enhanced experience for managing inbound integrations.
          • Auth Code Grant -- The OAuth authorization code grant is a secure and widely used flow for web, mobile, or desktop apps that access user data with user consent. It supports both private clients (using a client secret), and public clients (using PKCE).
            • Authorization Workflow -- ServiceNow handles both authentication and API access by acting as the authorization and resource server. When single sign-on (SSO) is enabled, it redirects users to the configured IdP for authentication and issues tokens after successful login.
            • Configuration -- Configure the OAuth authorization code grant to enable secure and interactive user authentication to enable applications to access resources on behalf of users. The OAuth authorization code grant verifies that the API access is granted based on the user identity and permissions.
          • Client Credentials Grant -- Use the OAuth client credentials grant type for back-end services or automated integrations that access ServiceNow APIs without user interaction. The client application authenticates directly using its client ID and secret, and receives an access token that represents the application itself, and not the user.
            • Client Credentials Workflow -- Authenticate a client application using a client credentials workflow. The client credentials grant workflow is used by back-end services or system integrations to access ServiceNow APIs without user involvement.
            • Configuration -- Configure the OAuth Client Credentials Grant for secure machine-to-machine authentication without user interaction. It authenticates applications using client credentials and grants-controlled API access with scoped permissions.
          • Third Party Token Grant -- The third party token grant enables ServiceNow to accept identity tokens from trusted external identity providers, such as Azure AD or Okta. Third party token grant provides secure, token-based access. This method supports secure access and single sign-on (SSO) in federated authentication scenarios.
            • User Token Flow -- This workflow can be used to integrate third-party identity providers (IdPs) with ServiceNow for secure API access. It allows client applications to obtain tokens directly from an IdP and use them to access ServiceNow APIs.
            • Service Token Flow -- Create a service account in ServiceNow to represent the identity of a third-party application accessing APIs through a trusted identity provider (IdP). This account maps the token claims to a user record and manages access with roles and permissions.
            • Configuration -- Configure a third-party ID token to enable secure authentication by verifying user identities through an external IdP. The third-party ID token improves security by reducing stored credentials, confirms seamless authentication, and supports interoperability with industry standards like OpenID Connect (OIDC).
          • JWT Grant -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction. Use this flow when a client application needs secure, unattended access to ServiceNow resources, either as itself or on behalf of a user.
            • Workflow -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction.
            • Configuration -- Configuring an OAuth JSON Web Token (JWT) bearer grant secures token-based authentication without user interaction. It enhances security with signed JWTs and reduces authentication overhead by eliminating repeated login attempts.
          • ROPC Grant -- Configuring an OAuth Resource Owner Password Credential (ROPC) grant enables applications to authenticate users by directly using their credentials to obtain an access token.
            • Password Grant Flow -- This flow is used in legacy or highly controlled environments where secure alternatives aren't feasible. The client app directly collects and sends user credentials to ServiceNow to obtain an access token, making it suitable only for trusted internal use.
            • Configuration -- Configuring an OAuth resource owner password credential (ROPC) grant enables applications to authenticate users by directly using their credentials to obtain an access token. This method is ideal for trusted applications and legacy systems that require authentication without browser-based flows, enabling secure token validation and controlled API access.
          • CIMD client integration -- CIMD lets the ServiceNow AI Platform accept an external OAuth client that identifies itself with an HTTPS metadata-document URL instead of a pre-issued client ID and secret.
            • CIMD workflow -- Configuring Client ID Metadata Document (CIMD) inbound support lets an instance accept an external OAuth client that's identified by a metadata document URL, without storing a client secret for that client.
            • Configure a CIMD client -- Register a Client ID Metadata Document (CIMD) client so that the instance accepts inbound OAuth requests from a client identified by a metadata document URL. You can fetch the client's configuration from its metadata URL or enter the details manually.
            • Update a CIMD client -- Update a registered Client ID Metadata Document (CIMD) client, including switching the metadata sync mode between Live and Static.
          • Old Inbound integrations experience -- Old experience - Inbound integrations.
          • OAuth authorization code grant flow -- Authorization code grant flow allows a user to access a resource by authenticating directly with an OAuth server that trusts the resource, in contrast with authenticating with username/password credentials.
          • Create an endpoint for clients to access the instance -- Create an OAuth application endpoint for external client applications to access the ServiceNow instance.
          • Create an OAuth JWT API endpoint for external clients (machine to machine integration) -- OAuth JWT bearer token enables the client web applications to authenticate with your instance seamlessly using the inbound JWT grant type instead of requiring the end user to manually log in or share the password.
          • Configure an OAuth OIDC provider for accepting third-party token -- Configure an OAuth OpenID Connect (OIDC) provider to accept identity tokens generated by a third-party OIDC provider using inbound API calls using Single Sign-On option (Multi-Provider SSO).
          • Configure client type for OAuth and SSO records -- Configure the Client Type field for OAuth and SSO record related configurations.
          • OAuth implicit grants -- ServiceNow instances support the implicit grant of an access token.
          • Client Credentials -- Use the OAuth client credentials grant type for Inbound Integrations from a third party OAuth client to the ServiceNow platform.
          • Manage OAuth tokens -- Open OAuth tokens to provide access to restricted resources.
          • Revoke an OAuth token -- You might want to revoke an OAuth access or refresh token for security reasons.
        • OAuth Outbound -- OAuth outbound enables you to pull data from a third-party provider to your instance.
          • Connect to a third-party OAuth provider -- Configure how the client ID and secret are sent to your OAuth provider.
          • JWT Bearer -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention.
          • Set up OAuth provider with JWT Bearer grant type -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
            • Upload Java Key Store certificate -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
            • Configure a JWT signing key -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
            • Create a JWT provider with a JWT signing key -- JSON Web Tokens (JWTs) enable the capability to configure server-to-server API interactions between ServiceNow and external API providers without requiring any user intervention. This support enables Integration Hub or other automated tasks using JWTs to configure API and Service integrations with different providers.
          • Generate a JSON Web Token (JWT) -- Create a JSON Web Token (JWT) for representing claims securely between two parties on the ServiceNow AI Platform.
          • OAuth client APIs -- The OAuth client API provides methods to request and revoke OAuth tokens.
          • OAuth parameters for default profile support -- The default profile feature requires a set of parameters that you can use with the setParameter() API to specify the OAuth requestor, a context for the request, and the provider profile.
          • Private Key JWT Support for OAuth 2.0 Client Authentication -- Support JWT Support for OAuth 2.0 Client Authentication.
          • Configure Private Key JWT for OIDC based SSO -- Configure Private Key JWT for OIDC based SSO integrations.
          • Configure Private Key JWT for Outbound OAuth -- Configure Private Key JWT for outbound OAuth integrations.
          • Create an outbound REST message -- Create outbound rest message to authorize instance as authorization server.
        • Personal authentication -- Personal authentication enables you to securely connect and manage your OAuth-based integrations like Microsoft OneDrive or Google Drive.
        • Configuration -- You can configure personal OAuth authentication with the REST step in Flow Designer.
        • Get OAuth Token -- Check whether the user has a personal OAuth token. Use it to confirm valid access before running REST steps or integrations that require personal OAuth credentials.
        • Generate Auth URL -- Generate the initial token for a user who doesn’t have access to the credentials page to configure personal authentication.
        • Activate Dashboard -- You can activate the Personal Authentication plugin (com.snc.sn_ihub_personal_auth) for Integration Hub if you have the admin role. If the application does NOT include demo data or it does NOT install related applications and plugins, delete or revise the following sentence:The application includes demo data and installs related ServiceNow Store applications and plugins if they are not already installed.
        • Self-register to ServiceNow instance -- Use external user self-registration to on-board a large volume of external users to your instance. This feature enhances identity verification to improve customer experiences and supports commonly used registration flows.
        • Explore Self-register -- Use external user self-registration to on-board a large volume of external users to your instance. This feature enhances identity verification to improve customer experiences and supports commonly used registration flows.
        • Activate External User Self-Registration -- You can activate the External User Self-Registration plugin (com.snc.external_user_self_registration) if you have the admin role.
        • Configure a user registration configuration for external users -- Create a user registration configuration record to bootstrap the onboarding process of external users to custom ServiceNow applications. This form guides the external users through the self-registration process.
        • Enable external user self-registration for Service Portal -- Enable external users to register to a ServiceNow app through Service Portal.
        • Verify user self-registration requests -- After a user registers from the Service Portal , a user record is added to the Registration Requests module. You can view the list of registered users who have successfully registered in the Service Portal .
        • Token based authentication (User logins) -- Enhance the security mechanism for users to access a network using token based authentication.
        • Time limited authentication -- Support time limited authentication for your ServiceNow instance.
        • Digest token authentication -- The digest token authentication passes user credentials and a digest token within an unencrypted HTTP header.
        • Web Embeddables -- Secure the web embeddables feature for authenticating the ServiceNow's web components that are used in third-party portals.
        • Configure client session access role -- The Embedded Session Role Configuration (Client Access Role configuration) record is created by default, which included removal of admin and security admin roles (high privilege roles) for the users using the UI components on the third-party portals.
        • Web service security -- Enforce security using basic authentication, mutual authentication, or WS-Security.
        • Explore Web service security -- Enforce security using basic authentication, mutual authentication, or WS-Security.
        • Configure mutual authentication -- Mutual authentication establishes trust by exchanging secure sockets layer (SSL) certificates.
      • Access Control Lists -- Access control lists (ACLs) restrict access to data by requiring users to pass a set of requirements before they can interact with it.
        • Explore Access Control Lists -- Explore access control lists (ACLs).
        • ACL types -- Create ACLs on different components of the system.
        • ACL control of function fields -- When evaluating access to a function field, in addition to checking access to the function field itself, the system also checks access to the function's contributing fields. Contributing fields are those used as the arguments in a given function definition.
        • Security jump-start - ACL rules plugin -- The Security jump-start access control level (ACL Rules) plugin is installed automatically on all new instances. Use this plugin to quickly secure multiple system tables and expedite the production launch process for your organization.
        • Configure an ACL -- Configure custom access control lists (ACLs) to secure access to new objects or to change the default security behavior.
        • Deny-Unless ACL -- Learn details about Deny-Unless ACLs.
        • Allow ACL -- Learn about Allow ACLs (access control lists).
        • Query ACLs -- Query ACLs allow you to define more granular access control by explicitly defining who can query the data.
        • Secure records in an embedded list -- To apply security to the records in embedded lists, limit editing and deleting records in embedded lists to specific roles.
        • Related record access -- Related record access enable consistent control over what records users are able to access between related tables.
        • Contextual Security Manager -- Contextual Security Manager protects your data by controlling read, write, create, and delete authorization.
        • Prevent duplicate entries with Contextual Security: Role Management V2 -- Roles inherited from other roles are added as individual entries in the User Roles table [sys_user_has_role], potentially causing one role to have duplicate entries. Contextual Security: Role Management V2 eliminates these duplicate entries and prevents future duplicates.
        • Upgrade to Contextual Security: Role Management V2 -- Contextual Security: Role Management V2 is automatically installed on new instances. You can upgrade from Contextual Security: Role Management to Contextual Security: Role Management V2 to eliminate duplicate roles in the User Roles table and prevent future duplicates.
        • Enable role auditing with Contextual Security: Role Management V2 -- Set a system property to enable the Audit Roles table to create audit records related to user roles.
        • Double-check form submission -- When the system determines that a particular field (such as task.number) should not be written to by the current user, the system renders that field in a read-only mode, which is why the number field is not writable on most incidents.
        • Default deny property -- The default deny property (glide.sm.default_mode) controls the security manager default behavior when the only matching ACL rules are the wildcard table ACL rules.
        • Advanced ACL configuration -- In addition to creating new ACLs or modifying existing ones, you can configure other aspects of ACL functionality.
        • Provide external users access to a table -- To enable users with only the snc_external role to access the list view of a table, you must create a series of ACLs.
        • Apply ACL script conditions to reference fields -- Use the glide.sys_reference_row_check system property to enable scripted conditions for reference fields.
        • Apply ACLs to AJAXGlideRecord (client-side Glide record) -- Use a system property to perform access control list (ACL) rule validation when server-side records (for example, tables) are accessed using GlideAjax APIs within a client script.
        • Evaluate the admin override at the access level -- If you want to force ACL evaluation for admin overrides at the access level, you can add a system property.
        • ACL debugging tools -- Field level debugging and access ACL rule output messages are available to help you troubleshoot and debug ACLs. The ACL configuration watcher lets you know what related ACLs exist when you modify one.
          • ACL troubleshooting reference -- ACL troubleshooting includes identifying ACL rule errors and use the debugging tools to fix the ACL related problems.
          • ACL configuration watcher -- The ACL configuration watcher lets you know what related ACLs exist on a table when you insert, update, or delete an ACL on the same table.
          • Show ACL execution plan -- Administrators can view how ACLs relate to each other by viewing an execution plan for any ACL in the instance.
          • Use the ACL configuration watcher -- Use the ACL configuration watcher after you elevate to security_admin role.
      • Access Analyzer -- ServiceNow Access Analyzer is an access diagnostic tool designed for AI administrators or creators to validate the access controls configured within various resources and agentic assets (agentic workflows and AI agents).
      • Access findings -- Access Findings is the proactive detection and remediation layer within Access Management Console. It runs eight out-of-box access checks against your instance on a daily schedule, surfaces prioritized findings when misconfigurations are detected, and provides a complete remediation workflow.
        • Explore Access findings -- Access Findings runs eight out-of-box access checks against your instance on a daily schedule, letting you know when misconfigurations are detected. It also provides a complete remediation workflow that includes AI-powered guidance.
        • Use Access Findings -- You can use Access Findings to view the potential vulnerabilities that were discovered the last time access checks ran on your ServiceNow AI Platform.
      • Access management console -- ServiceNow AI Platform's Access management console ensures that the right individuals have the appropriate permissions to the right resources at the right time.
        • Explore Access management console -- Use the Access Management Console within Security Center to review and remediate access issues and misconfigurations. The Access Management Console provides enhanced visibility and control of your Access Analyzer findings, and streamlines remediation efforts. Within the console you can track, prioritize, and resolve access issues by assigning tasks.
        • Use Access management console -- Use the Access management console to ensure that the right individuals have the appropriate permissions to the right resources at the right time.
      • Security Attributes -- Security Attributes offer a flexible alternative to access control lists.
      • Field Query Roles and Restrictions -- The Field Query Roles and Field Query Restrictionsattribute enable you to better control what information is available to users in tables.
      • Scripting Governance Tool -- Use the Scripting Governance Tool to provide a single, centralised control for managing scripting access across your ServiceNow AI Platform.
        • Explore Scripting Governance Tool -- The Scripting Governance Tool provides a single, centralised control for managing scripting access across your ServiceNow AI Platform.
        • Use Scripting Governance Tool -- Use the Scripting Governance Tool to provide a single, centralised control for managing scripting access across your ServiceNow AI Platform.
        • Scan for users who have scripted -- Scan your instance to find users who have scripted within a specific time frame. The scan queries the audit logs and identifies any user who has performed write or update to a table having script field.
        • Remove users from the Conditional Script Writer group -- Use the Manage scripting access to manually add or remove users from the Conditional Script Writer group to control who has scripting access.
        • Manage Scripting Governance Tool -- Enable or disable the Scripting Governance Tool on your instance by running the appropriate script. Only users with the security_admin role can run these scripts and modify the associated properties.
      • Machine identity access controls -- Define and enforce granular access control policies on specific resources for integration users.
        • Create a machine identity access control -- Enable administrators to define and enforce granular control for integration users by introducing User Access Profiles. This feature provides an additional layer of security and control, allowing admins to specify the exact resources (REST APIs and SOAP APIs) that an integration user can access, ensuring tighter governance and minimizing security risks.
      • Security Roles -- Security Roles provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
        • Explicit Roles -- You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
        • Request Explicit Roles -- You can give both internal users and external users access to your instance. However, you might not want both types of users to have the same level of access. To provide added security, every user must have at least one role so that the instance can distinguish between internal and external users.
        • Elevated privilege roles -- Elevated privilege roles require you to manually accept the responsibility of using the role before you can access the features of the role.
        • Security_admin role -- The security_admin role is an elevated privilege role provided with High Security Settings that lets users create and change access controls and change High Security Settings.
        • Elevate to a privileged role -- The base system admin can elevate to a privileged role to have access to the features of High Security Settings.
        • Force administrators to manually elevate -- A property is available to force all users with the administrator role to manually select the role that they want to elevate to.
      • Connections and Credentials -- Credentials and connection information are required to gain access to a computer or network device for Discovery, Service Mapping, and Cloud Management or to perform work using Orchestration. When adding content to Share or AppStore, you can configure connections and credentials relevant to your environment without modifying built content.
        • Explore credentials, connections, and aliases -- All application integrations in the ServiceNow AI Platform use connections, credentials, and aliases to enable applications to access resources.
        • Scope protections -- You can classify certain types of Connection & Credential records as belonging to a scope, and extend scope protections to them. These scope policies protect records you create in a table, and prevent interactions with records that are private to another scope.
        • Domain separation and Credentials and Connections -- Domain separation is supported in Credentials and Connections. Domain separation enables you to separate data, processes, and administrative tasks into logical groupings called domains. You can control several aspects of this separation, including which users can see and access data.
        • Connection & Credential configuration templates -- Enable users with the admin and flow_designer roles to set up spoke integrations with third-party systems using a single, customizable form.
          • Configure a template for OAuth JWT Bearer grant type -- This example configuration template sets up Credential and Connection records using the JWT Bearer grant type to authenticate requests to Docusign.
          • Create a configuration template -- Create a template that defines the inputs required to set up a spoke. Set static key-value pairs to create records and set values that apply to every integration. Set dynamic key-value pairs to gather user input and set field values that may vary. Using this template, admins and flow designers can set up the spoke from a single form.
        • Get started with connections -- Use the connections table to set up a Basic, JMS, JDBC, or HTTP(s) connection to a target host.
        • Create a basic connection for PowerShell and SSH -- Configure connection information to use with a custom activity or action that uses the PowerShell or Secure Shell (SSH) protocol.
        • Create an HTTP(s) connection -- The HTTP(s) connection provides the information custom HTTP(s) actions or activities use to connect.
        • Create a JDBC connection -- The JDBC Connection provides the information custom JDBC actions or activities use to connect to various target databases.
        • Create a JMS connection -- Configure your system to use Java Messaging Service (JMS) with a custom JMS activity or action.
        • Create connection attributes for IntegrationHub -- Define connection-specific variables that you can use in Integration Hub integration steps.
        • Get started with credentials -- The MID Server uses the credentials you create in the Credentials [discovery_credentials] table to access resources for Discovery, Orchestration, Service Mapping, and Cloud Management.
        • Create a Connection & Credential alias -- Define an alias to label a credential or connection record.
        • Set up OAuth integration via MID Server -- Create a connection record that enables the sending of an OAuth token request to a third-party server via a MID Server.
        • Credential aliases for Discovery -- Credential aliases for Discovery allow an administrator to use specific credentials on Discovery schedules. You can configure behaviors for your aliases that determine how strictly the system enforces their use.
          • Create a Discovery credential alias -- Credential aliases for Discovery allow an administrator to use specific credentials on Discovery schedules. You can configure behaviors for your aliases that determine how strictly the system enforces their use.
        • Credential aliases for Orchestration activities -- Credential alias gives an administrator more control over the credentials used in Orchestration activities.
        • Create and test your credentials -- Create and test the credentials that Discovery, Service Mapping, Cloud Management, and Orchestration require to access hardware and software in your network.
          • Ansible Tower credentials -- Ansible Tower credentials are required to access your Ansible configuration management account. Use these credentials to manage Ansible resources through the Cloud Management application.
          • API key credentials -- An API key is a unique code that is passed in to an API to identify the calling application or user.
          • Applicative credentials -- Some applications require credentials in addition to the credentials the that host machine requires. Credentials required to access these applications are referred to as applicative credentials.
          • Basic authentication credentials -- The basic authentication credential type manages access to store basic authentication credentials.
          • Chef server credentials -- Chef server credentials access chef integrations with the instance.
          • CIM credentials -- The CIM credential type manages access to a CIM server (also referred to as a CIMOM - Common Information Model Object Manager) for information about VMware ESX servers. This credential type is available for Discovery.
          • Configure NetApp storage devices for CIM credentials -- The CIM credential type manages access to a CIM server (also referred to as a CIMOM - Common Information Model Object Manager) for information about VMware ESX servers. This credential type is available for Discovery.
          • Cloud credentials -- Cloud credential types manage access to cloud-based applications, including Amazon Web Services and the Microsoft Azure cloud.
          • Container image repository credentials -- The container image repository credentials manage access to private repositories for container image scanning. This credential type is available for Discovery.
          • Infoblox credentials -- Infoblox credentials are required to set up IP pools (IPAM) in the Cloud Management application.
          • JDBC credentials -- The JDBC credential type manages access to a Java Database Connectivity (JDBC) connection. This credential type is available for Discovery and Orchestration.
          • JMS credentials -- The JMS credentials type manages access to a Java Message Service (JMS). This credential type is available for Discovery and Orchestration.
          • OAuth 2.0 credentials -- OAuth 2.0 credentials enable ServiceNow to obtain access to user accounts on an HTTP service.
          • SAP credentials -- The SAP credential type manages access to SAP JCo systems. This credential type is available for Discovery and Orchestration.
          • SNMP credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
          • SNMP community credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
          • SNMPv3 credentials -- Discovery explores many kinds of devices (switches, routers, printers, and so on) using the SNMP protocol. Credentials for SNMP don’t include a user name, just a password, called the community string.
          • SSH credentials -- Discovery, Orchestration, and Integration Hub explore UNIX and Linux devices by using SSH credentials to execute commands over Secure Shell (SSH). SSH commands must run with root privileges, either with root credentials or through the use of sudo. SSH private key credentials provide additional security.
          • VMware credentials -- The VMware credentials type manages access to vCenter credentials.
          • Windows credentials -- Windows credentials provide access to Windows computers. This credential type is available for Discovery and Orchestration.
          • Configure Windows credentials for the MID Server -- Windows credentials provide access to Windows computers. This credential type is available for Discovery and Orchestration.
        • Credential affinity for Discovery and Orchestration -- Credential affinity is an association between a set of credentials and a device on your network.
        • Credentials troubleshooting -- Review the section of the ECC queue payload to troubleshoot issues with credentials.
        • External credential storage -- An instance can store credentials used by Discovery, Orchestration, and Service Mapping in an external credential repository rather than directly in a ServiceNow credentials record.
        • Authentication Algorithms -- Verify the identity of the sender using Authentication Algorithms
        • Configure an authentication algorithm -- Configure an authentication algorithm so that you can sign outbound HTTP requests.
        • Configure an Amazon Signature based Custom Algorithm -- Generate the Amazon Signature based data needed to authenticate to a web service by running script.
        • Configure a custom authentication algorithm -- Generate the custom data needed to authenticate to a web service by running script.
        • Check IP service affinity for Discovery and Orchestration -- You can check the IP Services table for a list of IP addresses that are associated with a protocol.
        • ServiceNow access control -- The SNC Access Control plugin (com.snc.snc_access_control) enables you to control which Customer Service and Support employees can access your instance, and when.
          • Explore ServiceNow access control -- The SNC Access Control plugin (com.snc.snc_access_control) enables you to control which Customer Service and Support employees can access your instance, and when.
          • Activate ServiceNow access control -- You request activation of the SNC Access Control plugin (com.snc.snc_access_control).
          • Configure ServiceNow access control -- Configure an access control record to specify one or more Customer Service and Support employees who have permission to log in your instance.
          • Audit logging -- The following logging tracks logins and activity by ServiceNow employees.
        • Identity -- Know more about the Identities in the instance.
        • Global Identity -- Use ServiceNowGlobal Identity to help identify and manage users across multiple instances.
          • Exploring Federated ID -- The ServiceNow Identity system deduplicates users across multiple instances using their User ID and email, and assigns each resolved user a unique Federated ID for consistent identification.
          • Accessing Federated ID Criteria -- Access Federated ID Criteria to see the ID fields selected to generate the Federated ID unique identifier. The default setting is User ID and email.
          • Updating ID fields -- To generate new Federated IDs, you can either use the existing user resolution search criteria or update the criteria before regeneration.
        • Identity and Access Audit -- Use the Identity and Access Audit to understand changes made to users, groups, roles, and ACLs.
        • Identity Center -- Allows you to monitor, manage, and minimize identity-based risk and security gaps.
        • Machine Identity Console -- Manage your service accounts which are used for integrations with ServiceNow.
        • Role masking for AI agents -- Role masking for AI agents and agentic workflows helps administrators enhance security by limiting the roles those agents use during tool execution, and by verifying that AI agents run with least-access privileges.
        • System for Cross-domain Identity Management (SCIM) -- The System for Cross-domain Identity Management (SCIM) API provides endpoints to create, read, update, and delete operations on users and groups using the SCIM protocol.
          • SCIM Provider -- The Service Provider provisions users and groups using the SCIM API.
          • Exploring SCIM Provider -- The Service Provider provisions users and groups using the SCIM API.
          • Activating the SCIM plugin -- For SCIM activation, install the SCIM v2 - ServiceNow Cross-domain Identity Management (com.snc.integration.scim2) plugin.
          • Tutorial: Configure SCIM for user provisioning with a Provider -- Configuring SCIM automatically provisions and de-provisions users and groups to ServiceNow by using the providers provisioning service.
            • Provisioning user using Basic Authentication -- Configuring SCIM automatically provisions and de-provisions users and groups to ServiceNow by using the providers' provisioning service with Basic Authentication.
            • Provisioning user using OAuth -- Configure the provider for SCIM automatically provisions and de-provisioning of users and groups to ServiceNow by using the providers provisioning service with OAuth.
            • SCIM Troubleshooting -- Common error scenarios integrating with SCIM.
          • SCIM customization -- Customize SCIM protocols for your identity management.
          • Creating a source definition -- Create a source definition to capture information about which identity source a resource is provisioned from.
          • SCIM Client -- The SCIM Client facilitates provisioning and updates on identity resources through CRUD operations exposed by SCIM endpoint on an external system.
          • Exploring SCIM Client -- The SCIM Client facilitates provisioning and updates on identity resources through CRUD operations exposed by SCIM endpoint on an external system.
          • Activate the SCIM Client plugin -- For SCIM Client activation, install the SCIM v2 - ServiceNow Cross-domain Identity Management Client (com.snc.integration.scim2.client) plugin.
          • SCIM Client properties, tables, scriptable APIs, and logs -- The SCIM v2 - ServiceNow Cross-domain Identity Management Client (com.snc.integration.scim2.client) plugin includes the following system properties, tables, scriptable APIs, and logs.
          • Create a REST message -- Configure a REST message for all outbound calls for a particular SCIM Provider.
          • Create a SCIM Provider -- Create a SCIM Provider to fetch resource types and schemas information from the SCIM Provider with the REST message. Enable the configuration of the HTTP Method (PUT or PATCH) to update a resource in the SCIM Provider.
          • Create a SCIM Provider Resource Mapping -- Define the mappings of SCIM attributes to ServiceNow attributes for a particular resource type and SCIM Provider.
          • SCIM Client troubleshooting -- Troubleshooting actions can help resolve common issues when setting up or running the SCIM Client.
        • Access observer -- Use Access Observer to understand people and processes access data on your instance.
        • Configure access observation -- Create an access observation record to review access to a data column during a specified time window.
        • Review Access Observer logs -- Use information in the Access Observer log records for insights on how your data is accessed.
        • Granular admin roles -- Granular admin roles enables you to verify proper access management by assigning roles that define user permissions and responsibilities. By doing so, organizations can maintain security, enforce conformance, and optimize their operations effectively.
        • Platform security granular admin roles -- Use granular admin roles to verify access management by assigning roles that define user permissions and responsibilities.
        • Additional resources -- If you’re looking for Platform Security best practices, troubleshooting, or other implementation guidelines, select a feature or resource type to discover ServiceNow resources on other relevant websites.
        • Virtual infrastructure security -- Use virtualization with the flexibility to install multiple MID Servers in virtualized operating systems and networks in shared physical hardware.
        • Operating system security -- Learn how the MID Server stores its ServiceNow AI Platform username and password in its configuration file, named config.xml, for secure authentication to the instance.
        • Network security -- The MID Server communicates on port 443 using SSL to the instance and requires no inbound connections.
        • Agentic AI security and governance -- Now Assist AI agents operate securely within the boundaries you define. Layered controls govern who can invoke each agent, what data it can access, how interactions are monitored, and how your organization retains oversight.
        • Permissions-based access control -- Use Agent Role Inheritance, identity types, and granular roles to verify your AI agents have only the permissions they need, and can act only within their intended boundaries.
        • Data protection -- Learn how ServiceNow security tools such as the Key Management Framework, Field Encryption, and Data Classification work to keep your data secure.
        • Agent traceability and monitoring -- Learn how to use tools like AI Control Tower to track, monitor, and report on your AI assets.
        • Governance and admin safeguards -- Find guidance on preparing your instance for AI deployment, maintaining domain separation, and reducing risk across your Now Assist implementation.
        • AI threat protection -- Learn how Now Assist helps defend against AI-specific threats including offensive content, prompt injection, and sensitive subject detection using Now Assist Guardian.
        • External AI agent security -- Learn how to monitor and govern AI agents from external providers, with visibility into third-party data flows and assurances that sensitive data stays properly isolated across your AI ecosystem.
        • Now Assist Guardian -- Now Assist Guardian is built on the ServiceNow Small Language Model (SLM) and monitors generative AI interactions to detect offensive content, prompt injection attacks, and sensitive topics.
        • Create and secure an AI agent in Now Assist -- Plan, build, secure, test, and deploy a Now Assist AI agent.
          • Assess readiness -- Verify that your instance is prepared for AI agent deployment, install the required applications, assign the required roles, and classify user identity types before you begin building.
          • Plan your agent -- Define your use case, decide between an base system and custom agent, choose an activation model, and set your success criteria before you begin building.
          • Build your agent -- Create your agent in AI Agent Studio, configure its tools and knowledge sources, and set the access controls that determine who can invoke it and what data it can access.
          • Configure security controls -- Set up Now Assist Guardian guardrails and data privacy controls to protect your AI agent interactions before testing begins.
          • Test and validate -- Test your agent's execution and access controls, run automated evaluations, and review Guardian logs before approving the agent for production deployment.
          • Go live and monitor -- Deploy your agent to production, activate analytics and monitoring, and establish the ongoing review cadence that keeps your agent performing securely over time.
        • sndocs is an independent community mirror and is not affiliated with or endorsed by ServiceNow.

          ServiceNow, the ServiceNow logo, Now, and other ServiceNow marks are trademarks and/or registered trademarks of ServiceNow, Inc., in the United States and/or other countries. Other company and product names may be trademarks of the respective companies with which they are associated.

          © 2026 ServiceNow, Inc. All rights reserved.

          Documentation content is redistributed under the Apache License 2.0 from the ServiceNowDocs repository.