---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Deny internal access to explicit external roles \[Updated in Security Center 1.3 and 1.5\]

# Deny internal access to explicit external roles \[Updated in Security Center 1.3 and
1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use system properties to determine whether external users can be assigned the snc_internal role.
Use the glide.security.explicit_roles.enable_internal_user_blacklist system property to prevent external users from being assigned the snc_internal role. When this property is set to
true, it enforces the parameters of the maint-protected glide.security.explicit_roles.internal_user_blacklist property. This property assigns the snc_external
role to a list of untrusted user classes. If glide.security.explicit_roles.enable_internal_user_blacklist is set to false, the
glide.security.explicit_roles.internal_user_blacklist property is ignored.  
Hinweis:  
Instances without Explicit Roles installed are not affected. As of the Paris release, new installations of Explicit Roles get the property with a default value of true.

## More information {#sc-enable-explicit-roles-internal-denylist__section_qhx_1b1_xwb}

{#sc-enable-explicit-roles-internal-denylist__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.security.explicit_roles.enable_internal_user_blacklist |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Fallback value | false |
| Category | [Session management](https://servicenow-prod.fluidtopics.net/VAFB7gAR3D02VvnVYJ_a3g "This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.") |
| Security risk | * Severity score: 5.4 * CVSS score: Medium * Misconfiguration of this property increases the risk that an external user account gains access to internal information. {#sc-enable-explicit-roles-internal-denylist__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-enable-explicit-roles-internal-denylist__table_ajc_b43_3kb}

