---
sourceDocument: Australia Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - australia

ft:locale :

    - en-US

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Restrict knowledge bases access

# Restrict knowledge bases access {#ariaid-title1}

* Release version: Australia
* 
* Updated March 12, 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

The glide.knowman.block_access_with_no_user_criteria property is used to control the read/write access of users on knowledge based articles.
The glide.knowman.block_access_with_no_user_criteria system property is used in knowledge record user criteria security. If glide.knowman.block_access_with_no_user_criteria isn't set to the
recommended value of true, then knowledge bases without can read or can contribute user criteria become readable and writable by all users.

Ensure the property glide.knowman.block_access_with_no_user_criteria is set to true.

## More information {#sc-restrict-knowledge-bases-access__section_qhx_1b1_xwb}

{#sc-restrict-knowledge-bases-access__table_ajc_b43_3kb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.knowman.block_access_with_no_user_criteria |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | \<none\> |
| Fallback value | false |
| Category | [Access control](https://www.servicenow.com/docs/UcoTP53NgzpgtyyAIm1CdQ "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 9.1 * CVSS score: Critical * Security risk details: Knowledge bases lacking explicit "can read" or "can contribute" user criteria may become accessible and editable by all users, potentially leading to unauthorized access and modification of sensitive knowledge content. {#sc-restrict-knowledge-bases-access__ul_g1g_3sf_xwb} |
| Dependencies and prerequisites | None |
| Functional impact | Denies access to a knowledge base when either Can Read or Can Contribute isn't specified. |
[ ]

{#sc-restrict-knowledge-bases-access__table_ajc_b43_3kb}

