Combined Authentication release notes for upgrades from Yokohama to Zurich
Summarize
Summary of Combined Authentication Release Notes for Upgrades from Yokohama to Zurich
This consolidated guide helps ServiceNow customers prepare for upgrading their Authentication capabilities from the Yokohama release family to the Zurich release family. It highlights new features, changes, deprecations, and important upgrade considerations to ensure a smooth transition and improved security and integration experiences.
Show less
New Features
- Continuous Authentication (Yokohama): Enables step-up or re-authentication before users access sensitive or high-privilege data.
- OAuth Grant Types for MID Server (Yokohama): Supports multiple OAuth grant types (Authorization code, Resource owner password, SAML bearer, JWT bearer) for outbound integration requests through the MID Server, facilitating secure communication between ServiceNow and external systems.
- Machine Identity Console (Zurich): Simplifies inbound integration configuration with a new console designed for managing machine identity-based integrations.
- Multi-factor Authentication (MFA) Dashboard (Zurich): Provides insights on MFA user enrollment, privileged admin compliance, and overall MFA status to enhance security visibility.
- MFA Guided Setup (Zurich): Guides administrators through the MFA configuration process for users logging in with username and password, ensuring all users have an additional authentication layer.
- OIDC Attributes Filtering (Zurich): Allows using Identity Provider attributes received from OIDC responses as filter criteria for authentication policies.
Changes
- MFA Enforcement (Yokohama): MFA is mandatory for all non-SSO users accessing ServiceNow.
- Enhanced SSO Experience (Zurich): Improvements include displaying active SAML and OIDC Identity Providers on login pages, user group assignment during SAML/OIDC auto-provisioning, support for multiple SSO records using the same OIDC well-known URL, detailed login failure messages, and enhanced email notifications for SAML certificate and encryption key updates.
- FIDO2 Support (Zurich): Enforce hardware key or biometric second-factor authentication using FIDO policy for stronger MFA.
- OAuth Enhancements (Zurich): Increased client secret length support (up to 4096 characters), JWKS URL support for automatic JWT key management, expanded signing algorithm support (including Elliptic Curve and RS/HS variants), and customizable JWT ID (JTI) claim names for inbound OIDC and JWT flows.
Deprecations
- Inbound Integration Configurations (Zurich): Due to the new Machine Identity Console inbound integration configuration, legacy inbound integration setups via the Application Registry (OAuth API endpoint, OAuth JWT API endpoint, OIDC provider for ID token verification) are deprecated.
Activation and Requirements
- Authentication remains an active, default product within the ServiceNow AI Platform in both Yokohama and Zurich releases.
- There are no new additional or browser-specific requirements introduced with this upgrade.
- No changes to accessibility or localization requirements were noted.
Additional Highlights from Patch Releases
- AI Voice Service Authentication Factors: Enable caller access by configuring required authentication factors.
- OAuth Token Options: Support for Opaque or JWT tokens for inbound integration endpoints, with scope-based API access control.
- Provider Name Field: Introduced for inbound integrations to improve monitoring and management of OAuth and Basic authentication integrations.
- MFA Dashboard and Policies: Tools to monitor MFA enrollment and enforce FIDO-based second-factor authentication.
Practical Benefits for ServiceNow Customers
- Improved security posture through enforced MFA and enhanced authentication policies.
- Simplified integration management with the Machine Identity Console and expanded OAuth capabilities.
- Greater visibility and control over authentication activity via MFA dashboards and detailed SSO feedback.
- Streamlined upgrade process with clear deprecations and activation guidance.
Consolidated page of all release notes for Authentication from Yokohama to Zurich.
How to use this page
To help you prepare for your upgrade, we have combined the cross-family Authentication release notes onto one page. Read this summary of the new features, changes, and updated information for your product from Yokohama to Zurich.
Important information for upgrading Authentication to Zurich
Before you upgrade to Zurich, review these pre- and post-upgrade tasks and complete the tasks as needed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
New features
Between your current release family and Zurich, new features were introduced for Authentication.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Changes
Between your current release family and Zurich, some changes were made to existing Authentication features.
| Release | Release notes |
|---|---|
Yokohama |
|
Zurich |
|
Removed
Between your current release family and Zurich, some Authentication features or functionality were removed.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Deprecations
Between your current release family and Zurich, some Authentication features or functionality were deprecated.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
Due to the launch of new simplified inbound integration configuration in Machine Identity Console, the following inbound integrations configurations in the Application registry page are deprecated:
|
Activation information
Review information on how to activate Authentication.
| Release | Release notes |
|---|---|
Yokohama |
Authentication is a ServiceNow AI Platform product that is active by default. |
Zurich |
Authentication is a ServiceNow AI Platform product that is active by default. |
Additional requirements
If any additional requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Browser requirements
If any specific browser requirements were introduced or changed for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Accessibility information
Review details on accessibility information for Authentication, such as specific requirements or compliance levels.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Localization information
If there are specific localization considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
No updates for this release. |
Zurich |
No updates for this release. |
Highlight information
If there are specific highlight considerations for Authentication we have noted them here.
| Release | Release notes |
|---|---|
Yokohama |
Yokohama Patch 11
Yokohama Patch 7
Yokohama
See Authentication for more information. |
Zurich |
Zurich Patch 4
Zurich Patch 3
Zurich Patch 1
Zurich
See Authentication for more information. |