---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Activate session validation context

# Activate session validation context {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use session validation context to restrict access to ServiceNow® when hijackers copy a user's session cookies from one device to another to impersonate the session or restricts the user's session access if they're using an insecure network.

## Vorbereitungen

Role required: adaptive_auth_admin

To use the session validation, you must perform the following steps:

## Prozedur

1. Navigate to AllAdaptive AuthenticationAuthentication PoliciesAll Policies.
2. Select the Session Validation Policy in the Policies (<kbd class="ph userinput">sys_authentication_policy_list.do</kbd>) page.
3. Specify the Policy Inputs and Policy Conditions.
4. Set the conditions to true or false for the filters that you've added.
5. Select the Active check box to activate the policy after you set up the Session Validation Policy is set up with policy inputs and conditions.
6. Select a Force AuthnRequest check box for the default identity provider in the sso_properties table if the instance has SSO configured.
7. Navigate to AllAdaptive AuthenticationAuthentication PoliciesProperties.
8. Set the system property <kbd class="ph userinput">session.validation.enabled</kbd> to Yes.  

## Ergebnisse

The Session Validation feature is activated. You can configure the policy inputs and conditions for the policy to use the feature. To learn more, see [Tutorial: Configuring session validation](https://servicenow-prod.fluidtopics.net/Xj84ZAb2SgHBx1DxjD_Y4g "Configure session validation within the Adaptive Authentication framework to provide as an additional layer of protection for session or cookie hijacking.").

