Loading
Feature Disruption - Service Cloud VoiceRead More
Feature degradation | Gmail Email delivery failureRead More
Set Up and Maintain Your Salesforce Organization
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          Onboard EKM

          Onboard EKM

          With EKM you can use your key material housed in an external KMS. If you are currently using a Salesforce-generated root key or DEK, and you want to move to EKM, you can if the Shield Platform Encryption feature supports EKM. EKM is currently available for Platform Encryption for Data 360, Fields and Files (probabilistic), Fields (deterministic), Event Bus, and Shield Platform Encryption Search Indexes.

          Required Editions

          Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
          Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
          Available for free in Developer Edition.

          Prepare to use EKM

          To prepare for External Key Management we recommend these steps:

          Rotating To and From EKM

          You can rotate to EKM, and rotate back to a Salesforce tenant secret (or BYOK, if the feature supports it). To the Shield Platform Encryption process, it's just another secret. The topic Work with Salesforce Key Material describes key rotation concepts, considerations, and limitations.

          • EKM Considerations
            Take care when managing your external keys. Your Salesforce application depends on your external keys to encrypt and decrypt your data. If the key status changes, your users could permanently lose access to encrypted data.
           
          Loading
          Salesforce Help | Article