---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Prevent Unauthenticated Access to Virtual Agent Embedded Web Client

# Prevent Unauthenticated Access to Virtual Agent Embedded Web Client {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Learn how to configure the sn_va_web_client_app_embed table to block unauthenticated users from accessing embedded web clients.
The UI page, sn_va_web_client_app_embed, which is an embedded web client for Virtual Agent, contains the access control lists (ACLs) marked true in the sys_public table out of the box. It has been
confirmed that there are use cases where public accessibility is needed however this isn't a standard to set it to default publicly accessible.

If the embedded web client isn't needed for unauthenticated users, open the sn_va_web_client_app_embed record (sys_id <kbd class="ph userinput">04b1905473222300e985658b4cf6a7ef</kbd>) in the Public Pages
\[sys_public\] table and deselect the Active field to deactivate the page.

## More information {#sc-publicly-exposed-virtual-agent-embedded-web-client__section_qhx_1b1_xwb}

{#sc-publicly-exposed-virtual-agent-embedded-web-client__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | sn_va_web_client_app_embed |
| Configuration type | UI Page(sys_ui_page_list.do) |
| Data type | table |
| Recommended value | The sn_va_web_client_app_embed public page \[sys_public\] (sys_id <kbd class="ph userinput">04b1905473222300e985658b4cf6a7ef</kbd>) doesn't exist or isn't active. |
| Default value | Not available (this is a table value) |
| Category | [Access control](https://servicenow-prod.fluidtopics.net/xAmazkRh5FKyeb7q4TQGWw "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 7.5 * CVSS score: High * Security risk details: It is recommended to deactivate the UI page, sn_va_web_client_app_embed, if an embedded web client is not needed for unauthenticated users. {#sc-publicly-exposed-virtual-agent-embedded-web-client__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-publicly-exposed-virtual-agent-embedded-web-client__table_ajc_b43_3kb}

