Platform Analytics reports show a query on sys_dictionary ignored due to insufficient accessIssue <!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } When you build Platform Analytics reports or view data visualizations, the following error appears: Part of the query on sys_dictionary has been ignored because of insufficient access for the 'query_match' operation on sys_dictionary.display This error occurs because a May 2025 ServiceNow maintenance update applied changes to ACL configurations to enhance instance security. By default, query ACLs prevent users from querying fields to which they do not have access. Release<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } All supported releases Cause<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } Beginning with the Washington Patch 3 release, ServiceNow applied a proactive security maintenance update that modifies ACL configurations to prevent query_range requests from enumerating instance data without authorization. By default, query ACLs prevent users from querying fields to which they do not have access. When the platform encounters a restricted field, it ignores that part of the query and displays the error message. For more information about this maintenance update, see KB2046494 — May 2025 Maintenance Information. Resolution<!-- /*NS Branding Styles*/ --> .ns-kb-css-body-editor-container { p { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } span { font-size: 12pt; font-family: Lato; color: var(--now-color--text-primary, #000000); } h2 { font-size: 24pt; font-family: Lato; color: var(--now-color--text-primary, black); } h3 { font-size: 18pt; font-family: Lato; color: var(--now-color--text-primary, black); } h4 { font-size: 14pt; font-family: Lato; color: var(--now-color--text-primary, black); } a { font-size: 12pt; font-family: Lato; color: var(--now-color--link-primary, #00718F); } a:hover { font-size: 12pt; color: var(--now-color--link-primary, #024F69); } a:target { font-size: 12pt; color: var(--now-color--link-primary, #032D42); } a:visited { font-size: 12pt; color: var(--now-color--link-primary, #00718f); } ul { font-size: 12pt; font-family: Lato; } li { font-size: 12pt; font-family: Lato; } img { display: ; max-width: ; width: ; height: ; } } To resolve this error, use one of the following options. Option 1: Create query_match ACLs for sys_dictionary (recommended) Create a new query_match ACL for each affected field, or use a wildcard to cover all fields in the table: For individual fields: Operation: query_matchName: sys_dictionaryField: nameRole: Add roles based on your business requirements. Repeat for the display field: Operation: query_matchName: sys_dictionaryField: displayRole: Add roles based on your business requirements. For all fields (wildcard): Operation: query_matchName: sys_dictionaryField: * (wildcard — covers all fields in the table)Role: Add roles based on your business requirements. To identify which columns need new ACL rules, see KB2130442 — Troubleshooting query_range ACLs. Option 2: Disable field ACL enforcement for specific fields (Beginning with the Washington Patch 3 release) Create the following system property if it does not already exist: Name: disable_field_acl_enforcement.globalType: StringValue: sys_dictionary.name,sys_dictionary.display This disables field ACL enforcement for the specified fields only — it does not affect other ACL configurations. Note: To apply this to additional fields or tables, add them to the value as a comma-separated list in the format tablename.fieldname. Option 3: Suppress error messages (alternative — does not fix the underlying access issue) If you prefer not to modify ACLs or properties, create the following system property to suppress the error messages: Name: glide.db.encoded_query.field_acl_error_msgType: true or falseValue: false Note: This option suppresses the error messages only. The underlying query restriction on the affected fields remains in effect.