Use an External KMS for Key Management
Many organizations require direct control over the encryption keys that protect their business-critical data. Using an external key management service (KMS) addresses this requirement by allowing customers to maintain control of their encryption keys with a trusted external key management vendor. By providing direct control over encryption keys, using an external KMS significantly enhances the security posture for organizations, particularly those concerned about unauthorized access to these critical keys.
Furthermore, for many organizations, the ability to control their encryption keys externally is crucial for meeting various regulatory and compliance mandates. And direct control over encryption keys assists organizations in maintaining data sovereignty, which is important for legal and geographical considerations of data storage and access.
As of February 2026, Tableau Cloud offers external key management exclusively through the Amazon Web Services (AWS) KMS.
Note: External KMS features are available starting with Tableau Cloud February 2026 if you have Tableau +, Tableau Enterprise, or Advanced Management. If at some point you no longer have Tableau +, Tableau Enterprise, or Advanced Management, working with your encrypted objects will still work, but you won't be able to manage keys.
Features with external KMS support
You can use an external KMS to store encryption keys for:
- Extract encryption
- Data credentials encryption
Note: To use an external KMS for data credentials encryption, enable external KMS for extract encryption first.
Tableau encrypts both extracts and data credentials using the Salesforce-standard AES-GCM algorithm.
