Loading
Prepare for Email to Become the Default Login ExperienceRead More
Intermittent freezing when using using certain browser versionsRead More
Set Up and Maintain Your Salesforce Organization
Which User Permissions Does Shield Platform Encryption Require?

Which User Permissions Does Shield Platform Encryption Require?

Assign permissions to users according to their roles regarding encryption and key management. Some users need permission to select data for encryption, while other users require combinations of permissions to work with certificates or key material. Enable these permissions for user profiles just like you do for any other user permission.

Required Editions

Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
Available for free in Developer Edition.
Note
Note This content relates to Shield Platform Encryption. Read about implementing field-level encryption using Shield Extension in Own from Salesforce.
Key Management Task Required Permissions
View Platform Encryption Setup pages

Customize Application

View Setup and Configuration

Generate, destroy, export, import, and upload tenant secrets and customer-supplied key material Manage Encryption Keys
Query the TenantSecret object via the API Manage Encryption Keys
Edit, upload, and download HSM-protected certificates with the Shield Platform Encryption Bring Your Own Key service

Customize Application

Manage Certificates

Manage Encryption Keys

Enable features on the Encryption Settings page

Customize Application

View Setup and Configuration

Salesforce automatically enables the Customize Application and Manage Certificates permissions for users with the System Administrator profile.

You can also require admins to have the Manage Encryption Keys permission to complete encryption policy tasks such as encrypting fields and specific data stores, or changing a field’s encryption scheme. This restriction applies to actions taken through the API or the Salesforce UI. To turn on this feature, you must have the Manage Encryption Keys permission.

  1. From Setup, in the Quick Find box, enter Encryption Settings, and then select Encryption Settings.
  2. In the Advanced Encryption Settings section, turn on Restrict Access to Encryption Policy Settings.

    To turn on Restrict Access to Encryption Policy Settings via Metadata API, see PlatformEncryptionSettings.

 
Loading
Salesforce Help | Article