---
sourceDocument: Zurich Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/platform-security

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Prevent users from attaching unencrypted files

# Prevent users from attaching unencrypted files {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Modify the com.glide.encryption.enable_attachment_key_ui property to prevent your users with access to an encryption module key from attaching unencrypted attachments.

## Before you begin

Role required: security_admin

You must elevate to the security_admin role performing these steps. For instructions,
see [Elevate to a privileged
role](https://www.servicenow.com/docs/Pex7ZaqySC6GWg4WO_CjTQ "The base system admin can elevate to a privileged role to have access to the features of High Security Settings.")

By default, users who have access to an encryption module key are able to upload unencrypted attachments. Use the com.glide.encryption.enable_attachment_key_ui system property to change this behavior.

When attaching, your users see a UI picker on records that have a multi-module encrypted field configuration. When this property is set to false, users no longer see an option not to encrypt an attachment.

## Procedure

1. Navigate to AllSystem PropertiesAll Properties.
2. In the system properties list, find and open the system property.
3. Set the value of the property to <kbd class="ph userinput">false</kbd>.

*[\>]: and then


