SNC Access Control plugin (instance security hardening)

  • Release version: Washingtondc
  • Updated February 1, 2024
  • 1 minute to read
  • Activate the SNC Access Control (com.snc.snc_access_control) plugin to control access to your instances by Customer Service and Support personnel.

    The default configuration for the ServiceNow AI Platform enables Customer Service and Support to access instances through an internal process that creates short-term support credentials. Although all access is audited, some customers prefer to control this access.

    This plugin enables the customer administrator to prohibit Customer Service and Support employees from accessing the instance. This decision does have an impact on support SLAs because you must enable ServiceNow AI Platform access before support activities can begin. To learn more, see ServiceNow access control.

    More information

    Attribute Description
    Plugin Name com.snc.snc_access_control
    Configuration type System Definition > Plugins
    Configure in Instance Security Center Yes
    Purpose Prohibits Customer Service and Support employees from accessing the instance
    Recommended value Active
    Role required The customer administrator can't activate this plugin. It must be explicitly requested because it requires elevated privileges to activate the plugin.
    Functional ImpactIf this plugin is inactive, all Customer Service and Support employees can access the customer's instance. Enabling the plugin enables the customer to restrict access to authorized Customer Service and Support employees only.
    Security risk (Low) Unnecessary exposure of instance access to wider group of people.
    References ServiceNow access control

    Steps to configure

    1. To request the plugin, follow the steps in Activating ServiceNow access control. Customers must request the SNC Access Control plugin (com.snc.snc_access_control) from HI.
    2. To enable SNC access control, follow the steps in Configuring ServiceNow access control. Configure an access control record to specify one or more Customer Service and Support employees that have permission to log in your instance.