---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Prevent Empty ACL Creation \[New in Security Center 2.0\]

# Prevent Empty ACL Creation \[New in Security Center 2.0\] {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Set the glide.security.empty_acl.popup_window.enabled property
to the secure value of true to block attempts to create, update, or save an invalid ACL.
This setting will also provide a client-side model to configure a role or security attribute
for the ACL.
The glide.security.empty_acl.popup_window.enabled property
determines whether users making form-based edits to access control lists (ACLs),
specifically sys_security_acl, can create, update, or save an invalid ACL that has
an invalid data condition, script, security attribute, or roles
list.
Otherwise, it remains unconfigured (an empty ACL). As of the
Xanadu release, any empty ACL will deny access.
In ServiceNow versions prior to
Xanadu, an empty ACL will permit unconditional
access.

When the glide.security.empty_acl.popup_window.enabled property
is set to the secure value of true, it blocks attempts to create, update, or save an
invalid or empty ACL, and provides a client-side model to configure a role or
security attribute for the ACL. If the property is set to the unsecure value of
false, then such attempts will be permitted, and no client-side model will be
displayed.

Note: This property is case-sensitive. For example, a value of True (capital "T")
will be evaluated as false. Moreover, this property only functions when the High
Security (com.glide.high_security) plugin is installed and active.

## More information {#sc_prevent_empty_acl_creation__section_qhx_1b1_xwb}

{#sc_prevent_empty_acl_creation__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.security.empty_acl.popup_window.enabled |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | string |
| Recommended value | true |
| Default value | true |
| Category | [Validation, sanitization, and encoding](https://servicenow-prod.fluidtopics.net/F1nREUr0FIKK6cga6jbKwg "Validation, sanitization, and encoding addresses input validation to prevent against vulnerabilities like Cross-Site Scripting (XSS), SQL injection and other attacks.") |
| Security risk | * Severity score: 6.5 * CVSS score: Medium * Security risk details: If this property is set to true, the empty ACL warning popup will prevent the user from submitting an empty ACL on the client side. If it is set to false, the popup will no longer show. {#sc_prevent_empty_acl_creation__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
| Functional impact | This property allows the user to toggle the empty ACL warning popup on and off. |
| References | [Prevent Empty ACL Creation \[New in Security Center 2.0\]](pNNXRaXbVWdkYOAqQEADCQ "Set the glide.security.empty_acl.popup_window.enabled property to the secure value of true to block attempts to create, update, or save an invalid ACL. This setting will also provide a client-side model to configure a role or security attribute for the ACL.") |
[ ]

{#sc_prevent_empty_acl_creation__table_ajc_b43_3kb}

