With External Key Management (EKM), you encrypt data in Salesforce with key material
housed in an external key management service (KMS). If you currently use a Salesforce-generated
root key or DEK, you can switch to EKM for supported data stores and categories. Shield EKM
supports field-level encryption and encryption for data in Data 360, the event bus, and search
indexes.
Required Editions
Available in both Salesforce Classic (not available in all orgs) and Lightning
Experience.
Available in: Enterprise, Performance, and Unlimited
Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.
Prepare to Use EKM
External Key Management behaves differently than other Shield Platform Encryption
solutions. Take these steps before you get started.
Pay special attention to the section EKM Prerequisites. EKM only supports
keys created and stored in AWS KMS.
Rotating to and from EKM Keys
You can rotate to EKM keys, and rotate back to a Salesforce tenant secret (or Bring Your
Own Key, if the feature supports it). To Shield Platform Encryption, it's just another
secret. Read Work with
Salesforce Key Material for more information about key rotation concepts,
considerations, and limitations.
Shield External Key Management Considerations Your Salesforce implementation depends on your external keys to encrypt and decrypt your data. If the key status changes, your users can permanently lose access to encrypted data. Take these considerations into account when managing your external keys.
We use three kinds of cookies on our websites: required, functional, and advertising. You can choose whether functional and advertising cookies apply. Click on the different cookie categories to find out more about each category and to change the default settings.
Privacy Statement
Required Cookies
Always Active
Required cookies are necessary for basic website functionality. Some examples include: session cookies needed to transmit the website, authentication cookies, and security cookies.
Functional Cookies
Functional cookies enhance functions, performance, and services on the website. Some examples include: cookies used to analyze site traffic, cookies used for market research, and cookies used to display advertising that is not directed to a particular individual.
Advertising Cookies
Advertising cookies track activity across websites in order to understand a viewer’s interests, and direct them specific marketing. Some examples include: cookies used for remarketing, or interest-based advertising.