Loading
Set Up and Maintain Your Salesforce Organization
Table of Contents
Select Filters

          No results
          No results
          Here are some search tips

          Check the spelling of your keywords.
          Use more general search terms.
          Select fewer filters to broaden your search.

          Search all of Salesforce Help
          How Shield Platform Encryption Works in a Sandbox

          How Shield Platform Encryption Works in a Sandbox

          Refreshing a sandbox from a production org creates an exact copy of the production org. If Shield Platform Encryption is enabled on the production org, all encryption settings are copied to the sandbox, including tenant secrets created in production. This is true for all Shield Platform Encryption features.

          Required Editions

          Note
          Note This page is about Shield Platform Encryption, not Classic Encryption. What's the difference?
          Available in both Salesforce Classic (not available in all orgs) and Lightning Experience.
          Available in: Enterprise, Performance, and Unlimited Editions with the Salesforce Shield or Shield Platform Encryption licenses.
          Available for free in Developer Edition.

          After a sandbox is refreshed, tenant secret changes are confined to your current org. This means that when you rotate or destroy a tenant secret on the sandbox, it doesn’t affect the production org.

          As a best practice, rotate tenant secrets on sandboxes after a refresh. Rotation ensures that production and sandbox use different tenant secrets. Destroying tenant secrets on a sandbox renders encrypted data unusable in cases of partial or full copies.

          With Database Encryption, new keys are generated automatically in each sandbox via HSM.

          Tip
          Tip If you use the External Key Management Service, there are special considerations with sandbox key rotation. See External Key Management.
           
          Loading
          Salesforce Help | Article