Skip to main content

#Platform Encryption0 discussing

Hi all

My company has decided to enable encryption, but the process is a bit confusing for me since I haven’t done this before. Has anyone enabled both database-level and field-level encryption? Do we have to enable both? How do you manage your keys and handle backups?

I’m especially concerned about key management — whether it’s better to use the Salesforce-managed keys or go with BYOK. How do you handle key rotation and key backups?

#Shield/Platform Encryption #Encryption Key #Field Level Encryption #Shield Encryption #Encryption Discussion #Shield Platform Encryption #Encrypted #Deterministic Encryption #Platform Encryption
0/9000

Hello. 

 

I turned on Shield Platform Encryption in our Sandbox environment. I created a new custom text field and enabled 'encrypt the contents of this field'. Is there a way to also set a mask type and mask character? 

Thank you,

Nancy

 

#Shield/Platform Encryption  #Platform Encryption  #Salesforce

2 answers
  1. Sushil Kumar (UKG) Forum Ambassador
    Feb 15, 2024, 8:02 PM

    Nancy, I dont think Platform encryption supports masking. Its only for encrypting data at rest. Legacy encrypted fields do support masking. 

     

    Ref - https://help.salesforce.com/s/articleView?id=sf.security_pe_masking.htm&type=5

0/9000

We created a scratch org using Shape from our PROD and tried to deploy objects which we retrieved from PROD. Deployment is failing with following error:

 

Platform Encryption cannot be enabled for standard fields when Portals are enabled. (67:13)

 

But when I check, there are no portals enabled on the org. This issue wasn't there when trying to deploy on a normal scratch org.

4 comments
0/9000

Why are Custom object  date field (Deterministic Encryption) not allowed to be encrypted?

For custom Date fields - supported(Probabilistic Encryption) but Deterministic Encryption is not supported. do we have a chance date field enable to Deterministic Encryption

 

#Shield/Platform Encryption #Platform Encryption #Encryption 

1 comment
  1. Nov 8, 2021, 4:57 PM

    Hello i am currently facing the same issue and i cannot find a way to disable the customer portal manually in the setup or using the sfdx cli. Did you find something that could help resolve that issue?

0/9000

Hi All!

 

I am having an issue with Salesforce Shield, and its limitation with not being able to encrypt standard fields if Portal is enabled. In my project-scratch-def file (attached), I have no reference of Portals or Communities. They are also not enabled in my production instance. When I try to enable Probabilistic or Deterministic encryption for a standard field on the 'Encrypt Standard Fields' page I get the following error on save 'Platform Encryption cannot be enabled for standard fields when Portals are enabled. Client, Client Name'. When I search for 'Customer Portal Settings', in lightning i do not have this option, in classic i can see this option. I can see there is one portal (only in classic) enabled called 'Customer Portal', when i try to edit this i get the following error: 'The data you were trying to access could not be found. It may be due to another user deleting the data or a system error. If you know the data is not deleted but cannot access it, please look at our support page.'

 

Summary:

- This issue does not occur in production i can encrypt standard fields fine

- My project-scratch-def file does not contain any mention of Portal or communities as a feature

- I can only see the 'Customer Portal Settings' in classic, and trying to delete the portal gives an error.

 

Your help is much appreciated!

 

Many Thanks,

Shah

3 comments
  1. Nov 8, 2021, 4:54 PM

    Hello i am currently facing the same issue and i cannot find a way to disable the customer portal manually in the setup or using the sfdx cli. Did you find something that could help resolve that issue?

0/9000

Being new to Health Cloud I’m looking for guidance regarding Platform Encryption. Due to our HITRUST certification I’ve been evaluating the feature for possible utilization, but when reviewing the articles I seem to finding gaps in the REST API encryption e.g. Flows execute a Pause element. I guess the ultimate questions is…..to platform encrypt or not to platform encrypt?

0/9000

We are trying to push the encryptionScheme of a standard "Name" field of a custom object through DX using the object-meta.xml and it didn't throw an error message but it didn't enable the Platform Encryption too.

 

Have any one faced this?

 

I tried encrypting the same by manually going to the Name field and I can do it successfully,

 

It works fine on the Custom fields of both Standard and Custom objects and it could push it successfully.

1 comment
0/9000

@Chet Chauhan @Andrew Cafourek why is encryption at REST not an out of the box capability and instead a premium feature we have to pay for. Given that trust is salesforce's number 1 priority and that GCP, AWS and Azure offer this as standard.

 

“Nothing is more important to our company than the privacy of our customer’s data." — Parker Harris, salesforce.com EVP, Technology (https://www.heroku.com/policy/security)

 

#TTTC  #Security #Platform Encryption 

4 comments
  1. Oct 15, 2020, 5:15 PM
    @Dominic Young We are looking at sooner. There are efforts in flight at the moment - we'd love to connect with you on a call, and share more specifics.
0/9000

We are trying to implement Platform Encryption and already encountering a lot of limitations and issues. Who shall I go after to look for help? 

6 comments
0/9000
To provide broader support and expand the collaboration with our customers, we're extending the purpose of this group from Event Monitoring to all of Salesforce Shield, including Platform Encryption, Event Monitoring, and Field Audit Trail. We look forward to hearing from you!
0/9000