---
sourceDocument: Australia ServiceNow AI Platform Capabilities
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/servicenow-platform

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia ServiceNow AI Platform Capabilities

ft:clusterId :

    - platcap

bundleId :

    - platcap

workflow :

    - Platform


---

# Calculating the security score for password reset process

# Calculating the security score for password reset process {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

The security score of the password reset process is a critical metric for the password reset administrators to assess the strength and configuration of the password reset process.

## Password reset calculation {#pwd-reset-process-recommend__section_nqh_5cv_lfc}

The password reset process score provides a quantitative measure of how well the process is configured to protect against unauthorized access and confirm that only legitimate users can reset their passwords. The score is based on the following categories:

* Identification score (Max: 20 points)
* Verification score (Max: 40 points)
* Configuration score (Max: 20 points)
* Password policy score (Max: 20 points)
{#pwd-reset-process-recommend__ul_csd_wbw_lfc}

## Identification score {#pwd-reset-process-recommend__section_ktr_jfv_lfc}

To increase your identification score, you must enable multiple identification methods. If you're currently using only one method, such as a username, adding another method like an email can increase your score by approximately
five points. Additionally, enabling CAPTCHA adds 10 points to your score and help to prevent the bots from exploiting the password reset flow.

## Verification score {#pwd-reset-process-recommend__section_jxy_lfv_lfc}

To achieve a high score, you must use at least two verification methods with medium or high security levels. Each method adds up to 15 points (medium) or 25 points (high).

For the custom verification types, you must assign the security level. By default the custom verification is set as low.

## Configuration score {#pwd-reset-process-recommend__section_jmd_nbw_lfc}

To optimize your score, enable either the Email/SMS Password Reset URL or auto-generate passwords. If neither is enabled, the score is set at 10 points. Enabling either of these options fetches 20 points.

## Password Policy Score {#pwd-reset-process-recommend__section_sw1_pbw_lfc}

To maximize your Password Policy Score, enable the Password Policy on the Credential Store if it isn't active. Implement the Enforce History Policy to prevent users from reusing their last five passwords as defined in the
password_history_limit property. Use a High strength password policy and enable the following settings:

Send password reset process security score notification is a weekly job that send reminders to the password admin about the score and recommendations to improve the score. An email notification is sent to the
Process Owners of all the active processes if Enable security score notification option is selected in Password Reset Process form.
**Zugehörige Konzepte**   

* [Credential stores for Password Reset](https://servicenow-prod.fluidtopics.net/buvoo4XIOAgJ~PKhItvNwg "Credential stores hold user information such as user names and passwords that can be used as login credentials. Examples include the User table [sys_user] or an Active Directory server.")
* [Password Reset verifications](https://servicenow-prod.fluidtopics.net/Ls9L600FUEsllC0JKG9f~A "Each verification specifies the method and process for verifying the identity of the user that is requesting a password reset.")  
**Zugehörige Tasks**   

* [Configure password expiration reminder](https://servicenow-prod.fluidtopics.net/chxAPKC4Uksqp68fFhFLZA "You can configure the password reset expiration reminder feature to send notifications to change or reset a user’s password whenever it is going to expire.")
* [Configure your Password Reset process to auto-enroll users](https://servicenow-prod.fluidtopics.net/Z~cxlh~ruTRQpfFuOJNH5A "To simplify management, many organizations auto-enroll users in the Password Reset program. Every base-system verification type enables you to specify automatic enrollment for your process.")
* [Enable users to enroll for Password Reset](https://servicenow-prod.fluidtopics.net/dnwp9Ma0rsxh5WVALutJog "To enable users to enroll for the Password Reset program, you specify a UI macro that takes the user through the enrollment process and a script that processes the enrollment data that the user entered. The base system includes a functioning macro and script.")
* [Configure Password Reset properties](https://servicenow-prod.fluidtopics.net/83Dm8_sAgBsNGGfj0zy_Hg "You can specify properties that configure the Password Reset experience for end users.")
* [Send email to remind users to enroll for Password Reset](https://servicenow-prod.fluidtopics.net/cykyfREDKuW0IXYrR~jnpQ "You can automatically send messages that remind users to enrolled in the Password Reset process. You specify the text of the message and can configure the messages to repeat at intervals.")
* [Configure the required strength for passwords](https://servicenow-prod.fluidtopics.net/XtiMlgZjAHEv53bOFq2OMQ "The password that a user defines must meet certain requirements — for example, it must contain at least 12 characters, it must include a numeral, and so on. You can configure the requirements as needed for your organization.")
* [Specify lockout for failed login attempts](https://servicenow-prod.fluidtopics.net/WpU57WqqH17b8bPvrG6uZQ "The system provides inactive script actions that enable you to specify the number of failed login attempts before a user account is locked and to reset the count after a successful login.")
* [Configure Google reCAPTCHA for the password reset process](https://servicenow-prod.fluidtopics.net/fqOKwynU1VtjcxajD5khCQ "To use the Google reCAPTCHA service, instances that are running on a domain other than service-now.com require an API key pair from Google.")

