Onboard Database Encryption after Enabling Field-Level Encryption
If you have been using FLE, and have decided to take advantage of the benefits of
Database Encryption, decide whether you still need to use FLE. Database Encryption will cover
all standard and custom fields that you can configure with FLE without any issues with filtering
and sorting.
Required Editions
Available in both Lightning Experience and Salesforce Classic (not available in
all orgs).
Available in: Enterprise, Performance, and Unlimited
Editions using Hyperforce.
If you plan to stop using FLE on certain fields after Database Encryption is in place, you
should wait 24 hours before making any changes to them. After Database Encryption has been
enabled for at least 24 hours, turning FLE off on a field removes the encryption from the
field, so the field is temporarily unprotected. However, this change also forces the plain
text data to be rewritten, which will trigger Database Encryption to encrypt it right
away.
For fields that you must keep on FLE even after Database Encryption is enabled, you can
perform a no-operation or cosmetic change to the entity. This will trigger an encrypted write
to the transactional database for all entities of that type. (In fact you can use this
technique to trigger an encrypted write to any field, whether it is using FLE or not.)
Important
Once you have enabled Database Encryption, it remains in place. There is no option to turn
it off at the present time.
Also, you cannot synchronize existing data with the new active tenant secret. While key
rotation is supported, Salesforce automatically synchronizes data to the latest key over
time. There is no self-service sync option for Database Encryption.
To prepare for Database Encryption we recommend these steps:
Plan to test Database Encryption in a sandbox thoroughly before enabling it in your
production org.
If you plan to stop using FLE on certain fields after Database Encryption is in place, you
should wait 24 hours before making any changes to them. After Database Encryption has been
enabled for at least 24 hours, turning FLE off on a field forces the plain text data to be
rewritten, which will trigger Database Encryption to encrypt it right away.
For fields that you must keep on FLE even after Database Encryption is enabled, you can
perform a no-operation or cosmetic change to the entity. This will trigger an encrypted
write to the transactional database for all entities of that type.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.