---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Adaptive authentication

# Adaptive authentication {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Adaptive Authentication

Adaptive authentication in ServiceNow Brazil release enables you to enforce contextual authentication controls by evaluating authentication requests against defined policies.
This framework helps you restrict access to your instance based on criteria such as IP address, user role, and user group, ensuring that only the right users gain access at the right time.
Administrators can customize built-in policies to align with organizational security requirements, for example, allowing access only from trusted IP ranges for specific roles.
Show full answer Show less  

## Key Features

* **Authentication Policies:** These evaluate requests against set conditions and either allow or deny access accordingly. For example, an access policy might only allow users whose IP address falls within a trusted range and who belong to a defined role.
* **Authentication Policy Contexts:** Policies execute either before login (pre-authentication) or after credentials submission (post-authentication). Policies must be assigned to these contexts to be enforced appropriately during the login process.
* **Filter Criteria:** Inputs such as user role, IP address, and identity provider are used by policy conditions to validate authentication requests.
* **Authentication Properties:** Control settings for enabling adaptive authentication, debugging, and customizing user messaging when access is blocked.
* **REST API Access Policies:** Adaptive authentication filter criteria can also be applied to restrict inbound REST API access, enhancing security for integrations.
* **Domain Separation Support:** Adaptive authentication works in domain-separated instances, with policy conditions applying per domain or globally depending on configuration.
* **Adaptive Authentication Events:** A dedicated events table helps track authentication-related activities for monitoring and troubleshooting.
* **Customizable Messaging:** You can add custom messages in your instance's language for scenarios such as incorrect passwords, improving user experience and clarity.

## Practical Application for ServiceNow Customers

By leveraging adaptive authentication, you can enforce granular and context-aware access controls that improve your instance security posture. This means you can restrict login attempts based on trusted networks and user roles, control API access securely, and customize user messages for clearer communication during authentication failures. The policy contexts ensure that evaluation occurs at the most effective point in the login workflow, and support for domain separation maintains consistent security across segmented environments. Monitoring through events enables proactive management of authentication activities.  
Use the Adaptive authentication policy framework to enforce contextual authentication
controls to the right users at the right time. Adaptive authentication uses authentication
policies to evaluate authentication requests and then either deny or allow access to your instance
based on the specified policy conditions.

Use adaptive authentication policies and contexts to restrict the access to your instance for users and APIs based on criteria like IP address, user role, and user group. You can configure the built-in authentication policies
according to your security requirements.

For example, an administrator can configure the Allow Access Policy to allow logins from users only within a trusted range of IP addresses and who are members of a specific role. When assigned to the
Post-authentication context, the access policy denies access from untrusted IP addresses.

To set a custom message in the language of your instance you need to add key, value pair in <kbd class="ph userinput">sys_ui_message.list</kbd> and update the <kbd class="ph userinput">sys_ui_message</kbd> record. When you login with an incorrect
password, the custom message in the preferred language is displayed.

## Adaptive authentication components {#adaptive-authentication__section_yfj_2fz_qpb}

Authentication policies

:   Authentication policies evaluate authentication requests based on the specified policy conditions and either allow or deny access depending on the output of policy conditions evaluation. For example, access is allowed
    only if all the policy conditions specified in Allow Access Policy evaluate to true.

    Authentication policies use information provided by filter criteria to compare against the policy's conditions to determine whether to grant access to the instance. For example, a filter criteria provides a user's IP
    address, and a policy condition determines whether this address is within the specific range before granting access. Learn more about authentication policies in [Authentication policies](https://www.servicenow.com/docs/4CGNfvescQkE3rhsszgy5w "Authentication policies evaluate authentication requests based on the specified policy conditions and either allow or deny access depending on the output of policy conditions evaluation. For example, access is allowed only if all the policy conditions specified in Allow Access Policy evaluate to true.").

Authentication policy contexts
:   Authentication policy contexts define how and when policies are enforced during the login process. The pre-authentication context executes before the user is shown a login screen. The post-authentication context executes
    after the user enters their credentials. To use a policy, it must be assigned to a policy context. For details on these contexts, see [Authentication policy contexts](https://www.servicenow.com/docs/gmq9d3~ga~UraouqzmtZvQ "Use authentication policy contexts to determine how and when your instance enforces authentication policies.").

Filter Criteria
:   Filter criteria (also called policy inputs) are used as inputs for policy conditions. Policy conditions use these inputs to verify and meet the requirements of authentication requests. These inputs provide information
    like user role, IP range, and identity provider. For more detail on filter criteria, see [Filter criteria](https://www.servicenow.com/docs/FWAQEr9HgwblPhDVke4Tdg "Filter criteria (also called policy inputs) are used as inputs for policy conditions to verify and meet the requirements of an authentication request.").

Authentication properties
:   Use authentication properties to control whether adaptive authentication is active on your instance. You can also use properties to enabled debugging, and define the messaging users see when access is blocked. For details
    on these properties, see [Configure adaptive authentication properties](https://www.servicenow.com/docs/w2mcitOFuvdrduGevhDZYQ "After activating adaptive authentication, configure adaptive authentication properties according to your security requirements.").

## REST API access policies {#adaptive-authentication__section_qgj_fwy_v4b}

You can use the filter criteria of adaptive authentication framework to restrict access to inbound ServiceNow REST APIs. For more information, see [REST API access policies](https://www.servicenow.com/docs/t52e5ywGqB3rh4OITb25og "REST API access policies allow you to restrict access to inbound REST APIs based on the authentication type and the specified filter criteria of the access policy.").

## Domain separation and adaptive authentication {#adaptive-authentication__section_yxq_vrt_qpb}

Adaptive authentication is supported on domain separated instances on the authentication policy condition level. Policy conditions affect the domain in the records Domain \[sys_domain\] field. Policy
conditions in the global domain affect all domains.

## Adaptive Authentication Events {#adaptive-authentication__section_mrc_byj_zbc}

You can use the adaptive authentication events table to know about the events that have occurred specific to the adaptive authentication feature. For more information, see [Adaptive authentication events](https://www.servicenow.com/docs/2G~gBtyF0BjGtvnWP4MxVg "You can use the adaptive authentication events table to know about the events.").

