Loading
Prepare for Email to Become the Default Login ExperienceRead More
Set Up and Maintain Your Salesforce Organization
Onboard External Key Management

Onboard External Key Management

With External Key Management (EKM), you encrypt data in Salesforce with key material housed in an external key management service (KMS). If you currently use a Salesforce-generated root key or DEK, you can switch to EKM for supported data stores and categories. Shield EKM supports field-level encryption and encryption for data in Data 360, the event bus, and search indexes.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.

Prepare to Use EKM

External Key Management behaves differently than other Shield Platform Encryption solutions. Take these steps before you get started.

Rotating to and from EKM Keys

You can rotate to EKM keys, and rotate back to a Salesforce tenant secret (or Bring Your Own Key, if the feature supports it). To Shield Platform Encryption, it's just another secret. Read Work with Salesforce Key Material for more information about key rotation concepts, considerations, and limitations.

  • Shield External Key Management Considerations
    Your Salesforce implementation depends on your external keys to encrypt and decrypt your data. If the key status changes, your users can permanently lose access to encrypted data. Take these considerations into account when managing your external keys.
 
Loading
Salesforce Help | Article