Best Practice 2_Security: Servicenow Recommended Minimum Password Length As per Zurich Release

Tanushree Maiti
Mega Sage

Set minimal password length to avoid compliance issues and reduce the risk of a successful brute force attack.

Password Policy plugin (com.glide.password_policy) is enabled by default. The policy goes into effect when a user changes or resets the password. The Password Strength Preset field is automatically set to Default Strong.

TanushreeMaiti_0-1771176202240.png

 

For Default Strong , OOB Minimum password length is 8.

 

ServiceNow recommends to enforce a minimum password length of at least 12 characters to avoid compliance issues and reduce the risk of a successful brute force attack

 

For that open the record on the Password Policy [password_policy] record table and set the Minimum Password Length field to at least 12. You can find the associated Password Policy record in the Password policy field of the Password Reset Credential Store [pwd_cred_store] record.

 

Ref: https://www.servicenow.com/docs/r/platform-security/instance-security-hardening-settings/sc-set-mini...l

 

Please mark this response as Helpful & accept it as solution if it assisted you with your question.
Regards
Tanushree Maiti
ServiceNow Technical Architect
Linkedin:
0 REPLIES 0