---
sourceDocument: Zurich Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/zurich/platform-security

 Release :

    - zurich

ft:locale :

    - en-US

ft:publication_title :

    - Zurich Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Enable Cross Scope Privilege Checks on Service Portal Form \[New in Security Center 7.0\]

# Enable Cross Scope Privilege Checks on Service Portal Form \[New in Security Center 7.0\] {#ariaid-title1}

* Release version: Zurich
* 
* Updated July 31, 2025
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 minute to read

Use a system property to enforce cross scope privilege checks on the Service Portal form widget and prevent unauthorized retrieval of forms and table data between scopes.
In Yokohama and later releases, queries enforce cross scope privilege checks on the table before reading the given sys_id information.

When the glide.service_portal.enforce_cross_scope_check_in_form property is set to the recommended value of true, cross scope privilege checks are enforced on the table. When set to
false, the cross-scope privilege check isn't enforced.

Set the glide.service_portal.enforce_cross_scope_check_in_form system property to true or confirm that the property doesn't exist in the System Properties \[sys_properties\] table. If a
record doesn't exist in the sys_properties table, the value defaults to true.

## More information {#sc-enable-cross-scope-privilege-checks-on-service-portal-form__section_ghv_dvg_1xb}

{#sc-enable-cross-scope-privilege-checks-on-service-portal-form__table_hhv_dvg_1xb__entry__2}

| Attribute | Description |
|-|-|
| Configuration name | glide.service_portal.enforce_cross_scope_check_in_form |
| Configuration type | System Properties (/sys_properties_list.do) |
| Data type | Boolean |
| Recommended value | true |
| Default value | true |
| Category | [Access control](https://www.servicenow.com/docs/JtKgQWAhh8NqOL0ilKCKoA "The access control category audits the process of protecting resources from unauthorized access through granting and denying requests based on a permission model. This includes ensuring an entity accessing a resource holds valid credentials to do so, creating and protecting a well-defined set of roles or permissions and ensuring role or permission controls are protected from replay and tampering.") |
| Security risk | * Severity score: 3.1 * CVSS score: Low * Security risk details: A lack of cross scope privilege checks could lead to unauthorized retrieval of forms and table data between scopes. {#sc-enable-cross-scope-privilege-checks-on-service-portal-form__ul_ihv_dvg_1xb} |
| Dependencies and prerequisites | None |
[ ]

{#sc-enable-cross-scope-privilege-checks-on-service-portal-form__table_hhv_dvg_1xb}

