---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# High Assurance

# High Assurance session with Continuous Authentication {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Establish high assurance session for with ServiceNow's continuous authentication.

A high assurance session is a security measure to establish a secure and trusted connection with the identities (users) who access data and are verified with a high degree of confidence.

ServiceNow's High assurance is achieved through robust authentication methods which enforces re-authentication using methods such as Multi-factor Authentication (MFA) and Single Sign On (SSO) while the users
try to access data that are sensitive.

When the user re-authenticates or perform step-up authentication (MFA), there's a high assurance session that is established, which provides the ability for the users to access the data protected by the CA administrator based on the
CA policy configuration.

Following are the re-authentication methods used to establish High-assurance based on the type of login:

* [High Assurance for SSO login](https://servicenow-prod.fluidtopics.net/AAswyijQqTWq5_Dru_wdsg "Establish high assurance session for SSO login using ServiceNow's continuous authentication.")
* [High Assurance for non-SSO login](https://servicenow-prod.fluidtopics.net/_lxL0kGDrWbslo3GV2nPqw "Establish high assurance session for non-SSO logins (local or LDAP) using ServiceNow's continuous authentication.")

{#high-assurance-ca__ul_ztz_kk2_ddc}

High assurance session created by the user is valid based on the High Assurance session length (glide.zta.high_assurance.session.timeout) determined by the CA administrator.

The high assurance session can be customized based on your requirement by setting the High Assurance system properties:
{#high-assurance-ca__table_tfb_2l2_ddc__entry__2}

| Field | Description |
|-|-|
| High Assurance session length (glide.zta.high_assurance.session.timeout) | Specify the high assurance session length, after which the end-users should re-authenticate. Default: 30 minutes. Hinweis: The value must be between 1 and 480. |
| Default high-assurance session length upon login | Specify the duration in minutes for the default high-assurance session length upon user login. Default value: 5 minutes. Hinweis: This property is only applicable for non-sso logins. |
| Configure end-user display message (glide.zta.high_assurance.session.message) | Specify the message that is displayed to the end-user for re-authentication. Default message: <kbd class="ph userinput">One or more resources require additional authentication due to a policy created by your administrator</kbd>. |
| Total times failed authentication before user account lock-out (glide.zta.high_assurance.session.max.login.failed_attempts) | Set the maximum failed authentication attempts before the users are logged out. Hinweis: The value must be between 3 and 10. |
[Tabelle : 1. High Assurance system properties]

{#high-assurance-ca__table_tfb_2l2_ddc}

## High assurance session as a Preemptive measure {#high-assurance-ca__section_hwl_g32_d2c}

Users who work with high privilege data such as financial transactions, government information, PII, can establish high assurance session as a
preemptive measure to avoid frequent authentication notification during their logged in session.

High assurance session can be created by the themselves. To create a high assurance session, select User ProfileProfile. In the Related Links section, select Create High-Assurance Session. Verify your identity to create a high assurance session.
**Zugehörige Konzepte**   

* [Exploring Continuous Authentication](https://servicenow-prod.fluidtopics.net/fMbsn97SSru4LU1WEADEzw "ServiceNow's continuous authentication (CA) enables you to re-verify and authenticate a user if they access resources that are protected by you.")
* [Pre-work for Continuous Authentication](https://servicenow-prod.fluidtopics.net/fRWAJJwkvHoeR8vYcd7Onw "Ensure to perform the following pre-work before using Continuous Authentication (CA).")  
**Zugehörige Tasks**   

* [Configuring Continuous Authentication](https://servicenow-prod.fluidtopics.net/vxILJeY6MlUQ2JYcUouTNA "Configure continuous authentication (CA) policies to re-authenticate the users if there's an attempt to access resources that are protected by you.")

