---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enable policy based session access for mobile \[New in Security Center 1.5\]

# Enable policy based session access for mobile \[New in Security Center 1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Use the The Zero Trust- Policy Based Session Access plugin to control if users authenticating through a mobile app will have their roles reduced.
The Zero Trust- Policy Based Session Access plugin enables security admins to reduce user access in a session based on parameters such as IP address, location, identify provider attributes, and user attributes with adaptive
authentication policies. When this plugin is enabled or set to true, users authenticating through a mobile device will have their roles restricted according to the plugin's policies. Instance admins may wish to restrict high
privileged access when users authenticate through a mobile device as it could indicate an unsafe environment for sensitive operations.

## More information {#sc-enable-policy-based-session-access-for-mobile__section_more_information}

{#sc-enable-policy-based-session-access-for-mobile__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.authenticate.session_access.mobile.enabled |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 4.7 * CVSS score: Medium * Security risk details: If this hardening setting is set to true, then policy based session access is enforced on the instance for mobile logins, and users that are not coming from a trusted environment, or are not using trusted devices will have their roles with reduced privileges. True is the secure setting. If this setting is configured to false, then policy based session access is disabled, and users will continue to have full roles including the high privileged roles like admin all the time. {#sc-enable-policy-based-session-access-for-mobile__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
| Functional impact | If admin has configured the session access policy on the instance, then users will have their roles reduced after mobile login if they are not coming from a trusted environment or using a trusted device. |
| References | [Adaptive authentication](https://servicenow-prod.fluidtopics.net/XQ5OEG0LBshxmWwXEKVReg "Use the Adaptive authentication policy framework to enforce contextual authentication controls to the right users at the right time. Adaptive authentication uses authentication policies to evaluate authentication requests and then either deny or allow access to your instance based on the specified policy conditions.") |
[ ]

{#sc-enable-policy-based-session-access-for-mobile__table_ajc_b43_3kb}

