Loading
Feature degradation | Gmail Email delivery failureRead More
Set Up and Maintain Your Salesforce Organization
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          EKM Prerequisites

          EKM Prerequisites

          To use EKM, you must create a data encryption key (DEK) of sufficient strength in a supported external key management service. You should also check that an external application can communicate with the key service to securely retrieve the DEK.

          Required Editions

          Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
          Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the External Key Management Service. Data 360 customers must also have the Platform Encryption for Consumption license.
          User Permissions Needed
          To generate, destroy, export, import, upload, and configure tenant secrets and customer-supplied key material: Manage Encryption Keys

          Salesforce EKM supports AWS Key Management Service key material only. Refer to the AWS KMS documentation for information about creating, accessing, and managing keys in AWS.

          AWS KMS Key Requirements

          Before you configure your connection in Salesforce, create your key material in AWS KMS. Salesforce requires:

          • Symmetric key type
          • Single region (MultiRegion = False)
          • An ARN that’s in the same AWS region as the current Hyperforce instance within which your core org resides.

          Make sure that you can access key material in both Salesforce and AWS KMS.

          Exercise careful accounting between the Salesforce Key Management Setup page and the AWS KMS dashboard. AWS KMS has no information about the status of Salesforce EKM secrets.

           
          Loading
          Salesforce Help | Article