Migrate from Customer-Managed Encryption Keys to External KMS

Note: Switching from customer-managed encryption keys to an external key management service (KMS) is permanent and can't be undone. For more information on using an external KMS, see Use an External KMS for Key Management.

Migrating from customer-managed encryption keys (which use Salesforce's KMS) to an external KMS is simple, but it's permanent and can't be undone. After the change, you’ll manage your keys in the external KMS instead of Salesforce's KMS. Be sure that you understand how to perform basic key functions in the external KMS before you migrate from customer-managed encryption keys to an external KMS.

After the migration, the key derived from the external KMS will write new extracts. The Salesforce KMS key will continue to read extracts that it wrote, until the extracts are refreshed with the external KMS-based key.

For more information on customer-managed encryption keys and the Salesforce KMS, see Customer-Managed Encryption Keys(Link opens in a new window).

To migrate from customer-managed encryption keys to an external KMS:

  1. Log in to your Tableau Cloud site.
  2. Select Settings in the left navigation pane.
  3. Select the Security tab.
  4. Under the Extract Encryption section, change the selection from Use the Salesforce KMS to Use an external KMS.
  5. Read the warning, then select Switch to External KMS.
Thanks for your feedback!Your feedback has been successfully submitted. Thank you!