---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enforce field ACLs for inbound query requests

# Enforce field ACLs for inbound query requests {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Manage how incoming queries are validated on your instance.
Use the glide.export.query.enforce_field_acl property to check how incoming queries are validated on your instance. If the property is set to the recommended value of true, field ACLs are
checked against incoming queries, and rejected if the user is unauthorized. If the property is set to false, ACLs are not checked against incoming queries and continue to execute which can lead to information
disclosure to unauthorized parties.

## More information {#sc-enforce-field-acls-for-inbound-query-requests__section_ghv_dvg_1xb}

{#sc-enforce-field-acls-for-inbound-query-requests__table_hhv_dvg_1xb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.export.query.enforce_field_acl |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | false |
| Category | [Architecture, design, and threat modeling](https://servicenow-prod.fluidtopics.net/GP7csKl7x_IoFFA7nE_oew "This broad control addresses high level design considerations and key elements to implement a secure application. This covers the tenants of availability, confidentiality processing integrity, non-repudiation and privacy. Additionally, elements of a secure software development lifecycle are included.") |
| Security risk | * Severity score: 4.4 * CVSS score: Medium * Security risk details: If this property is set to false, ACLs are not checked against incoming queries which can lead to information disclosure. {#sc-enforce-field-acls-for-inbound-query-requests__ul_ihv_dvg_1xb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-enforce-field-acls-for-inbound-query-requests__table_hhv_dvg_1xb}

