Loading
Prepare for Email to Become the Default Login ExperienceRead More
Salesforce Enforces New Security Requirements in Summer 2026Read More
Set Up and Maintain Your Salesforce Organization
Turn on Encryption for Backup & Recover Next

Turn on Encryption for Backup & Recover Next

To encrypt data backups, turn on encryption for Backup & Recover Next. Salesforce creates a root key for you and begins encrypting your data.

Required Editions

Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
Available in: Enterprise, Performance, Unlimited, and Developer Editions. Requires purchasing Salesforce Shield or Shield Platform Encryption, and the Backup & Recover Data and Backup & Recover Files add-on licenses.
User Permissions Needed
To generate, destroy, export, import, upload, and configure key material: Manage Encryption Keys
To view and edit Setup: View Setup and Configuration

Backup & Recover root keys encrypt backups made with Backup & Recover Next. These root keys don’t encrypt data backups made with Backup & Recover for Salesforce or the legacy Salesforce Backup.

  1. From Setup, use the Quick Find box to find and select Encryption Settings.
  2. Turn on Manage Backup & Recover Keys.
    Salesforce generates a root key for you. When it’s ready, see your key on the Key Management page under the Backup & Recover tab.
  3. To make your key easier to identify during audits, edit the root key’s description.
    1. From Setup, use the Quick Find box to find and select Key Management.
    2. In the Root Key Inventory section under the Backup & Recover tab, click Details.
    3. Click Edit Description.
    4. Add a unique description and save your work.

From now on, your Backup & Recover Next root key secures the data encryption keys that encrypt backups stored at rest.

 
Loading
Salesforce Help | Article