- Post History
- Subscribe to RSS Feed
- Mark as New
- Mark as Read
- Bookmark
- Subscribe
- Printer Friendly Page
- Report Inappropriate Content
yesterday
“Can a user impersonate an authorized user to gain access to encrypted fields?”
“What if an Admin impersonates a user to gain access to encrypted data?”
These questions come up frequently. Platform Encryption Module Access Policies are designed to address this risk: by default, users with the admin role are blocked from accessing encrypted fields through impersonation. While impersonation can allow a user, including an admin, to assume another user’s access, there are important limitations and controls that can block impersonation-based access altogether.
Key considerations
- When you impersonate a user, you assume that user’s profile, including the roles associated with it. The main limitation is that you cannot impersonate someone whose privileges are higher than those of the account you are impersonating from. (i.e. – a regular user couldn’t impersonate a Security Admin or Admin)
- If an admin impersonates another user, the admin can typically assume that user’s assigned roles, with the exception of the security admin role. (Assigning the security admin role to an admin is very rare and not typically recommended.)
How to block impersonation-based access to encrypted data
The ability to block impersonation is configured directly within each Module Access Policy. As shown in the image below, leaving ‘Impersonation’ unchecked prevents users from impersonating roles to access encrypted data.
**REMINDER - This setting is unchecked by default, so access through impersonation is only allowed if a user explicitly selects it during the creation of a MAP.
