---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enforce password reset on api requests \[Updated in Security Center 1.5\]

# Enforce password reset on api requests \[Updated in Security Center 1.5\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Manage how the password reset functionality operates on your instance.
When a user is marked for Password needs reset, they must provide a new password at the next authentication attempt. This property controls whether the password reset is mandatory before
making API calls. If this property is not set to the recommended value of true, user accounts marked as Password needs reset can still perform operations by querying the table API
through basic authentication. This security vulnerability could enable information leakage if an inactive account is compromised.

## More information {#sc-enforce-password-reset-on-api-requests__section_ghv_dvg_1xb}

{#sc-enforce-password-reset-on-api-requests__table_hhv_dvg_1xb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.authenticate.api.user.reset_password.mandatory |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Category | [Session management](https://servicenow-prod.fluidtopics.net/VAFB7gAR3D02VvnVYJ_a3g "This category looks at the security of the application state for a user. Sessions should be unique to each individual, unable to be guessed or shared, and invalidated after periods of inactivity or when not required. This includes factors such as cookie attributes for cookie-based sessions, session token generation, and storage and requirements for federated re-authentication.") |
| Security risk | * Severity score: 8.1 * CVSS score: High * Security risk details: Setting this property to false could lead to information leakage if an inactive account is compromised. {#sc-enforce-password-reset-on-api-requests__ul_ihv_dvg_1xb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-enforce-password-reset-on-api-requests__table_hhv_dvg_1xb}

