---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Baseline version 7.0

# New hardening settings for baseline 7.0 {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

New hardening settings have been released with Security Center baseline version 7.0.

* [Enable Cross Scope Privilege Checks on Service Portal Form \[New in Security Center 7.0\]](YIc5BsqdoGnt3gVQiXSJEg "Use a system property to enforce cross scope privilege checks on the Service Portal form widget and prevent unauthorized retrieval of forms and table data between scopes.")
* [Validate query ACLs on Glide DB functions \[New in Security Center 7.0\]](ZDxojC7Kx8MWF~T6rA6HoA "Control whether query ACLs are applied to Glide DB functions using system properties.")
* [Use Document Classification to limit publicly accessible documents \[New in Security Center 7.0\]](iioCwGUPj7Q7UPOcE2Of3w "Control public access to permalinked documents using system properties.")
* [Restrict write access on system fields to admin users \[New in Security Center 7.0\]](DJAZ77KQZIU6cqYorJt7ew "Use the glide.rest.table_api.admin_only_sys_fields system property to control write access the fields generated by the system.")
* [Require approval for agent-based Office 365 group membership changes \[New in Security Center 7.0\]](tUfBX~w33iX_H_5JEwGfng "Enable the approval flow for adding or removing Office 365 group members through the Microsoft 365 group membership AI Agent using a system property.")
* [Exclude Sensitive Tables and Fields from Data Generation \[New in Security Center 7.0\]](5OH06ofmglEqJMe6gZNmnQ "Use system properties to exclude tables and fields from Data Generation, which is used to generate fake data sets based on existing data. Tables and fields that are added to these exclusion lists can't be used for Data Generation feature.")
* [Enforce Read Roles for Catalog Variable Search \[New in Security Center 7.0\]](X1QmkuV~XlPHkYmIszTD~w "Use system properties to ensure that only catalog variables with an empty read role are indexed for search.")
* [Enforce valid query string choice \[New in Security Center 7.0\]](iXe3LbpYn4A~FwTaI66JXg "Use a system property to ensure that any choice field value, when passed via a URL query string, is a valid active choice when a record is created.")
* [Restricted Binding functionality in case Bearer Authorization \[New in Security Center 7.0\]](etGPjwNvsph49pqCnS1EuQ "Use a system property and restricted binding to ensure that an access token generated using that entity can’t be used for UI calls.")
* [Disable resource owner password credentials (ROPC) in OAuth 2 token grants \[New in Security Center 7.0\]](eFbcHPTL0oZVtBT4_Ilz2w "Prevent Resource Owner Password Credentials (ROPC) from granting OAuth 2 tokens.")
* [Enforce certificate trust \[Updated in Security Center 1.3, removed in 2.0, added in 7.0\]](Cx1dyxQIyLlkzrCjBnFWiw "Use system properties to ensure that certificate expiration and trust are checked for certificates received from outbound HTTPS call endpoints when host verification is not performed.")
* [Prevent usage of 3DES keys \[New in Security Center 7.0\]](eqv8Ju2GSw~oOLXWDq4GCg "Disable the use of 3DES static keys on your instance with a system property.")
* [Allow HTML Links to Trusted Domains in the Description Fields of the Impact Workspace Module \[New in Security Center 7.0\]](fl_Rv4OfCPBtKLPcdieP6g "Use a system property to help sanitize the HTML allowed in the descriptions fields. This property limits the allowed links to only those from the trusted domains listed in the property.")
* [Ensure Contextual Search Do Not Contain An Unvalidated Redirect \[New in Security Center 7.0\]](fHuzjabGCn7mQU9pCCFC~g "Prevent Contextual Search results from containing referral links outside the current domain with a system property.")
* [Sanitize HTML in the Description Fields of the Impact Workspace Module \[New in Security Center 7.0\]](gd_xBdRTbs2jirgNJl1rkg "Sanitize the HTML in the description fields by removing HTML tags that are sources of HTML injection attacks with the sn_impact_common.blacklist_tags_HTML_injection property.")
{#new-hardening-settings-for-baseline-seven__ul_em2_1rj_xfc}

