---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configure an ACR user

# Configure an account recovery user {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Configure an account recovery user to perform account recovery activities on your
instance.

An account recovery user is a user account that administrators can use to perform account
recovery tasks, such as addressing an SSO misconfiguration or addressing expired
certificates.  
Hinweis:  
If you are using account recovery on your instance, you must configure an account recovery user. This step is necessary before enabling multiple-provider single sign-on on an instance.

## Configure an account recovery user from the Account Recovery Properties page {#ariaid-title2}

Configure an account recovery from the Account Recovery properties page.

### Vorbereitungen

Role required: sso_config_admin, business_rule_admin, script_include_admin

For a fresh instance to configure ACR, you must do the following:

* Activate Mutli-SSO plugin (<kbd class="ph userinput">com.snc.integration.sso.multi.installer</kbd>)
* Enable ACR (<kbd class="ph userinput">glide.sso.acr.enabled</kbd>) - This is enabled by default in case of a fresh instance.
* Before enabling SSO property (<kbd class="ph userinput">glide.authenticate.multisso.enabled</kbd>), the administrator must enroll as an ACR user.
* Administrator must set a password for local login and register MFA before enrolling as an ACR user.

{#config-acct-recovery__ul_hkw_wxq_jrb}

For an upgraded instance to use ACR, you must do the following:

* Activate Mutli-SSO plugin (<kbd class="ph userinput">com.snc.integration.sso.multi.installer</kbd>)
* Enable ACR (<kbd class="ph userinput">glide.sso.acr.enabled</kbd>)  
  Hinweis:  
  In case of upgraded instance, the administrator must enable ACR.
* Before enabling SSO property (<kbd class="ph userinput">glide.authenticate.multisso.enabled</kbd>), the administrator must enroll as an ACR user.  
  Hinweis:  
  Setting this property to false will not disable multi-provider SSO if Account Recovery (ACR) is also enabled on the instance. To log in with a username and password ACR must also be disabled using the glide.sso.acr.enabled property. For details on this property see [Account recovery properties](https://servicenow-prod.fluidtopics.net/H4w4UMF1PjRGpqFTRfcrNA "Use system properties to configure Account Recovery (ACR) on your instance.").
* Administrator must set a password for local login and register MFA before enrolling as an ACR user.
{#config-acct-recovery__ul_vkq_t22_krb}

### Prozedur

1. Navigate to AllAccount RecoveryProperties.
2. Click Enable account recovery.  
   Hinweis:  
   You need to enable account recovery when SSO is enable. Account recovery users will be limited to SSO configuration and troubleshooting-related tasks.
3. Click the here text in the Step 2.  
4. Following the on-screen directions in the Configure account recovery for Multi-SSO modal.  
   After completing the on-screen steps, the Enable account recovery is enabled.
5. Click Enable account recovery.

### Ergebnisse

You have configured your user account as an account recovery user. You can verify this account, and see any other configured account recovery users by navigating to Multi-Provider SSOAccount RecoveryUsers.

## Configure an account recovery user from an admin user profile {#ariaid-title3}

Configure an administrator as an account recovery user from the admin user
profile.

### Vorbereitungen

Role required: sso_config_admin, business_rule_admin, script_include_admin

### Prozedur

1. Log into your instance using an administrator account.
2. Click on the user name in the instance header, and select Profile.  
3. In the User form, click Enable Account Recovery in the Related Links section.  
   Hinweis:  
   If the selected user already has account recovery enabled, Enable Account Recovery does not appear in the related links. There will be a Disable Account Recovery option instead.
4. Following the on-screen directions in the Configure account recovery for Multi-SSO modal.  
   After completing the on-screen steps, the Enable account recovery is enabled.
5. Click Enable account recovery.

### Ergebnisse

You have configured your user account as an account recovery user. You can verify this account, and see any other configured account recovery users by navigating to Multi-Provider SSOAccount RecoveryUsers.

