When you want to revoke all access to encrypted data, or rotate keys as a part of
planned maintenance, you can deactivate key material. The effect of deactivating key material is
similar to that of deleting a key. Your data remains encrypted, but it can’t be
decrypted.
Required Editions
Available in both Lightning Experience and Salesforce Classic (not available in
all orgs).
Available in: Enterprise, Performance, Unlimited, and
Developer Editions. Requires purchasing Salesforce Shield or Shield
Platform Encryption, and the External Key Management Service. Data 360 customers
must also have the Platform Encryption for Consumption license.
User
Permissions Needed
To generate, destroy, export, import, upload, and configure
tenant secrets and customer-supplied key material:
Manage Encryption Keys
Consider the effect on your users and data of deactivating the EKM key. Data encrypted
with the key isn’t decryptable. Make sure that the data you need is synchronized to a different
key.
From Setup, in the Quick Find box, enter Platform Encryption, and
then select Key Management.
In the External Key Inventory, click Details for the key you want to
deactivate.
In the pane that opens, review the information. Then click either Never
Mind or Deactivate External Key.
Communicate with any other key managers that the key is now deactivated. Be alert for users
reporting an inability to access encrypted data they could see
previously.
Did this article solve your issue?
Let us know so we can improve!
Loading
Salesforce Help | Article
Cookie Consent Manager
General Information
Required Cookies
Functional Cookies
Advertising Cookies
General Information
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.