Migrating to Field Encryption

  • Release version: Australia
  • Updated March 10, 2026
  • 1 minute to read
  • Scheduled jobs migrate your keys and encrypted data from Encryption Support to Field Encryption.

    When you install Field Encryption, the migration process triggers automatically. Once the key migration job completes, encryption context keys are restricted to decryption only. Use cryptographic module keys for all new encryption operations going forward.

    You can review the scheduled jobs by navigating to System Security > High Security Settings > Security Jobs:

    • autoKeyMigration: Migrates encryption context keys to Key Management Framework (KMF) cryptographic module keys.
    • autoDataMigration: Migrates data that you already encrypted to use the KMF cryptographic module key.

    You can modify when these scheduled jobs run, and can pause or restart them at any time.

    Verify that the encrypted field configurations are using your newly migrated module keys by navigating to System Security > Field Encryption > Encrypted Field Configurations. Look for the following items:
    • The Method field is Single Module.
    • The Crypto module field is populated with the name of the cryptographic module that the system automatically creates. You can review that module and the module access policy, both of which are active and published.