Activate External Key Management Service

  • Rversion finale: Australia
  • Mis à jour 12 mars 2026
  • 1 minute de lecture
  • Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.

    Avant de commencer

    Roles required: admin, security_admin, and sn_kmf.cryptographic_manager

    Dependencies:

    The following plugins need to be already installed on your environment:
    • Key Management Framework Scoped App
    • Field Encryption Enterprise

    Pourquoi et quand exécuter cette tâche

    Activating EKMS installs the necessary components to encrypt ServiceNow data with external keys managed in AWS Key Management Service.

    Procédure

    1. Navigate to All > System Definition > Plugins.
    2. Under Search your licensed applications and plugins, search for Platform Encryption External Key Management.

      The search should reveal the plugin. If you purchase a subscription for External Key Management Service, you can also see this plugin available.

      Important :
      To activate External Key Management Service, you must first purchase a subscription to the service and its dependencies: Field Encryption Enterprise and Key Management Framework Scoped App. Your account manager can arrange to have the plugin activated on your organization’s production and non-production instances.
    3. Select Install
      Remarque :
      When domain separation and delegated admin are enabled in an instance, the administrative user must be in the global domain. Otherwise, the following error appears: Application installation is unavailable because another operation is running: Plugin Activation for <plugin name>.

    Résultats

    The EKMS plugin is now installed and activated. You can proceed to configure your external key integration.

    Que faire ensuite

    Next steps:

    • Set up AWS Key Management Service access
    • Configure the EKMS key definition in ServiceNow