---
sourceDocument: Yokohama Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/yokohama/platform-security

 Release :

    - yokohama

ft:locale :

    - en-US

ft:publication_title :

    - Yokohama Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Disable local login for users with Single Sign-On (SSO) enabled

# Disable local login for users with Single Sign-On (SSO) enabled {#ariaid-title1}

* Release version: Yokohama
* 
* Updated June 18, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Update user records to disable local login for users with Single Sign-On (SSO) enabled.
Users configured to use SSO authentication may be able to access the instance, or parts of the instance, with local credentials stored in the user_password field of their User \[sys_user\] record. This access
applies to both interactive and non-interactive access for users who aren't locked out. Help prevent SSO-configured users from using local credentials to reduce the chance that valid local login credentials are stolen and used by
malicious users.

Review Now Support Knowledge Base article [KB1649420](https://support.servicenow.com/kb?id=kb_article_view&sysparm_article=KB1649420) for instructions on identifying and addressing accounts with local login still enabled on an instance with SSO enabled.

## More information {#sc-disable-local-login-for-users-with-single-sign-on-sso-enabled__section_lnh_pkf_32c}

{#sc-disable-local-login-for-users-with-single-sign-on-sso-enabled__table_zyc_nlf_32c__entry__2}

| Attribute | Description |
|-|-|
| Security risk | When SSO authentication is enabled for a user, it's best practice to prevent that user from logging in locally. This reduces the chance that the valid local login credentials are stolen and used to login by a malicious user. |
| Common Vulnerability Scoring System (CVSS) score | 4.2 |
| Common Vulnerability Scoring System (CVSS) rating | Medium |
| Functional impact | SSO configured users are able to log in with local credentials. |
| Dependencies and prerequisites | Single Sign-On must be enabled (the glide.authenticate.multisso.enabled system property set to true.) |
| Data type | N/A |
| Base system value | N/A |
| Fallback value | N/A |
| Recommended value | N/A |
[ ]

{#sc-disable-local-login-for-users-with-single-sign-on-sso-enabled__table_zyc_nlf_32c}

