Combined Authentication release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Authentication release notes for upgrades from Yokohama to Zurich
This document consolidates all Authentication-related release notes for ServiceNow customers upgrading from the Yokohama release family to Zurich. It provides a comprehensive view of new features, changes, deprecated functionalities, and important upgrade considerations to help you prepare and execute your upgrade efficiently.
Show less
New Features
- Continuous Authentication: Requires step-up or re-authentication before granting access to sensitive or high-privilege data (introduced in Yokohama).
- OAuth Grant Types for MID Server: Supports Authorization code, resource owner password credential, SAML bearer, and JWT bearer grants for outbound integrations via MID Server.
- Machine Identity Console (Zurich): Simplifies inbound integration configuration, streamlining setup and management.
- Multi-factor Authentication (MFA) Dashboard (Zurich): Provides insights on MFA user enrollment, privileged admin compliance, and overall MFA status.
- MFA Guided Setup (Zurich): Helps administrators configure MFA for users logging in with only username/password, enhancing security through step-by-step guidance.
- OIDC Attribute Filtering (Zurich): Uses Identity Provider attributes from OIDC responses as filter criteria for authentication policies.
Key Changes
- MFA Enforcement: MFA is mandated for all non-SSO login users to improve security (Yokohama).
- Enhanced SSO Login and Logout (Zurich): Improvements include displaying active SAML and OIDC IdPs on login pages, user group assignment during auto-provisioning, shared well-known URLs for OIDC configurations, detailed login failure messages, and better logout handling.
- FIDO2 as MFA Factor (Zurich): Enables enforcement of hardware key or biometric second-factor authentication.
- OAuth Integration Enhancements (Zurich): Support for client secrets up to 4096 characters, JWKS URL for automatic JWT public key updates, expanded JWT signing algorithms, and customizable JWT ID claims for inbound OIDC and JWT Bearer flows.
Deprecations
- Zurich deprecates legacy inbound integration configurations in Application Registry, including OAuth API endpoints, OAuth JWT API endpoints, and OIDC provider verification, in favor of the new Machine Identity Console inbound integration setup.
Activation and Requirements
- Authentication remains an active default ServiceNow AI Platform product in both Yokohama and Zurich releases.
- No additional browser or localization requirements were introduced between Yokohama and Zurich.
Additional Highlights
- Authentication Factors for AI Voice Service: Available in both Yokohama Patch 11 and Zurich Patch 4, enabling caller access to AI voice agents via configured authentication factors.
- Provider Name Field for Inbound Integrations: Introduced to enhance monitoring by distinguishing inbound integrations via provider names (Zurich Patch 3).
- OAuth Token Options: Opaque or JWT token options are supported for inbound integration endpoints, improving flexibility and security (Yokohama Patch 7 and Zurich Patch 1).
Practical Guidance for ServiceNow Customers
When upgrading from Yokohama to Zurich, review and complete pre- and post-upgrade tasks to ensure smooth transition. Leverage the new MFA dashboard and guided setup to enforce multi-factor authentication effectively. Use the Machine Identity Console to simplify inbound integration configuration and replace deprecated legacy setups. Take advantage of enhanced OAuth and SSO capabilities to strengthen your organization's authentication security posture.
Consolidated page of all release notes for Authentication from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Authentication release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Authentication to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Authentication.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Authentication features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Authentication features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Authentication features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Due to the launch of new simplified inbound integration configuration in Machine Identity Console, the following inbound integrations configurations in the Application registry page are deprecated:
|
Activation information
Review information on how to activate Authentication.
| Release | Release notes |
|---|---|
Yokohama |
Authentication is a ServiceNow AI Platform product that is active by default. |
Zurich |
Authentication is a ServiceNow AI Platform product that is active by default. |
Additional requirements
If any additional requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Authentication, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Localization information
If there are specific localization considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
Yokohama Patch 11
Yokohama Patch 7
Yokohama
See Authentication for more information. |
Zurich |
Zurich Patch 4
Zurich Patch 3
Zurich Patch 1
Zurich
See Authentication for more information. |