Combined Authentication release notes for upgrades from Xanadu to Zurich
Summarize
Summary of Combined Authentication Release Notes for Upgrades from Xanadu to Zurich
This document consolidates the release notes for ServiceNow Authentication from the Xanadu through Zurich releases, helping customers understand key new features, changes, and deprecations to prepare for upgrading Authentication to the Zurich release.
Show less
Authentication remains an active ServiceNow AI Platform product by default across all releases.
New Features
- Yokohama Release: Introduced Continuous Authentication to require step-up or re-authentication before granting access to sensitive information. Added support for various OAuth grant types (Authorization Code, Resource Owner Password Credential, SAML bearer, JWT bearer) for outbound integration requests through MID Server.
- Zurich Release: Launched Machine Identity Console for simplified inbound integration management. Introduced a Multi-factor Authentication (MFA) Dashboard to monitor MFA enrollment, privileged admin compliance, and overall MFA status. Added MFA Guided Setup to assist administrators in enforcing MFA for users currently using username and password only. Enabled filtering authentication based on attributes from OIDC identity provider responses.
Changes
- Xanadu: Expanded MFA factor options to include FIDO2 authenticators, passkeys, biometric authenticators, and hardware security keys without requiring an authenticator app setup.
- Yokohama: Mandated MFA for all non-SSO login users.
- Zurich: Enhanced the Single Sign-On (SSO) login and logout experience with features such as displaying active SAML and OIDC IdPs on login pages, assigning users to groups during SAML/OIDC auto-provisioning, supporting multiple OIDC configurations using the same well-known URL, and improving login failure messaging. Added enhanced email notifications for SAML certificate and encryption key updates. Introduced FIDO2 enforcement policies as an MFA factor. OAuth integrations now support longer client secrets, JWKS URL for automatic public key updates, and additional JWT signing algorithms with customizable JWT claim names.
Deprecations
- Xanadu: Deprecated MultiSSO v1 plugin—customers should upgrade to MultiSSO v2. Also deprecated SAML 1.1 plugins and OpenID SSO plugin; these have been replaced by configurations under MultiSSO v2 for SAML 2.0 and OIDC support.
- Zurich: Deprecated certain inbound integration configurations in the Application Registry due to the new Machine Identity Console, including OAuth API endpoints for external clients and OIDC provider verification methods.
Additional Highlights
- OAuth inbound integrations now allow specifying a Provider name to improve monitoring and distinguish between integrations.
- OAuth enhancements include support for opaque and JWT token types, scope-based API access control, and resource parameter configuration for outbound integrations.
- Authentication factors for AI voice services have been introduced to enable caller access by configuring required identification and authentication factors.
Upgrade Guidance
Before upgrading to Zurich, it is important to review and complete any pre- and post-upgrade tasks related to Authentication. Customers should especially note plugin deprecations and migrate accordingly to maintain support and functionality.
Familiarize yourself with new MFA and SSO enhancements to improve security posture and user experience.
Consolidated page of all release notes for Authentication from Xanadu to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Authentication release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Xanadu to Zurich.
Important information for upgrading Authentication to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Authentication.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Authentication features.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Authentication features or functionality were removed.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Authentication features or functionality were deprecated.
| Release | Release notes |
|---|---|
Xanadu |
|
Yokohama |
No updates for this release. |
Zurich |
Due to the launch of new simplified inbound integration configuration in Machine Identity Console, the following inbound integrations configurations in the Application registry page are deprecated:
|
Activation information
Review information on how to activate Authentication.
| Release | Release notes |
|---|---|
Xanadu |
Authentication is a ServiceNow AI Platform product that is active by default. |
Yokohama |
Authentication is a ServiceNow AI Platform product that is active by default. |
Zurich |
Authentication is a ServiceNow AI Platform product that is active by default. |
Additional requirements
If any additional requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Authentication, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Localization information
If there are specific localization considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
No updates for this release. |
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Xanadu |
See Authentication for more information. |
Yokohama |
Yokohama Patch 11
Yokohama Patch 7
Yokohama
See Authentication for more information. |
Zurich |
Zurich Patch 4
Zurich Patch 3
Zurich Patch 1
Zurich
See Authentication for more information. |