---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Do not apply password policy at login \[Updated in Security Center 1.5 and removed in 2.0\]

# Do not apply password policy at login \[Updated in Security Center 1.5 and removed in
2.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Manage how password complexity is handled in your instance.
By setting the property glide.apply.password_policy.on_login to false
there will be no password complexity enforcement at login time. Setting the property to true
will enforce password complexity and lead to organization policy compliance issues.

As per ASVS 4.03 v2.1.9 recommendations:

"Verify that there are no password composition rules limiting the type of characters
permitted. There should be no requirement for upper or lower case or numbers or special
characters. (C6)"

Instead of password complexity enforcement, ASVS recommendations are to enforce a minimum
length of 12 characters for password length.

Refer to [OWASP ASVS v4.0 Authentication](https://github.com/OWASP/ASVS/blob/master/4.0/en/0x11-V2-Authentication.md).

## More information {#sc-do-not-apply-password-policy-at-login__section_qhx_1b1_xwb}

{#sc-do-not-apply-password-policy-at-login__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.apply.password_policy.on_login |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | false |
| Default value | false |
| Category | [Authentication](https://servicenow-prod.fluidtopics.net/faHnGPrE5YkSR8Xq~3OW5g "The authentication category covers the main elements of modern authentication to confirm an entity and its claims are authentic and correct, resistant to impersonation and prevent interception of passwords.") |
| Security risk | * Severity score: 4.4 * CVSS score: Medium * Security risk details: Setting this property to true could enforce password complexity and lead to organization compliance issues. {#sc-do-not-apply-password-policy-at-login__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-do-not-apply-password-policy-at-login__table_ajc_b43_3kb}

