---
sourceDocument: Brazil Platform security
sourceDocumentLink: https://www.servicenow.com/docs/r/platform-security

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# External Key Management Service

# External Key Management Service {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of External Key Management Service

The External Key Management Service (EKMS) in ServiceNow allows you to integrate Field Encryption with your own external key management systems, currently supporting AWS Key Management Service (AWS KMS).
EKMS lets you retain direct control over encryption keys that protect your data on the ServiceNow platform by generating, storing, and managing keys outside the ServiceNow infrastructure.
This approach supports cloud-based enterprise services while ensuring sensitive data remains secure under your control.
Show full answer Show less  

## Key Features

* **Key Lifecycle Control:** Manage the entire lifecycle of your encryption keys including generation, rotation, and revocation to quickly respond to security events.
* **Key Wrapping Architecture:** Uses a multi-layer key wrapping chain where the External Key Encryption Key (EKEK) is wrapped by the Instance Root Key (IRK), which is further wrapped by your AWS KMS symmetric key, ensuring secure access control.
* **Synchronization:** A configurable background job synchronizes AWS key states (enabled, disabled, pending deletion, deleted) with your ServiceNow instance every 30 minutes by default.
* **Integration with Field Encryption Enterprise (FEE):** EKMS works with cryptographic modules that use the external AWS KMS key to wrap data encryption keys, and encrypted field configurations specify which table columns are encrypted.
* **Access Control:** Module Access Policies (MAPs) control which user roles can decrypt and view encrypted data, enhancing data protection by restricting access to authorized users only.

## Key Limitations

* Only one EKMS configuration can be set up per ServiceNow instance.
* Multi-region AWS KMS keys are not supported.
* The AWS KMS key used must be a symmetric key.

## Getting Started and Activation

To activate EKMS, you must purchase a subscription to either Platform Encryption or ServiceNow Vault, which includes Field Encryption Enterprise and Cloud Encryption. Then, install the Field Encryption Enterprise plugin and the EKMS plugin (com.glide.encryption.externalkms). After installation, configure EKMS by connecting your AWS KMS credentials and setting up cryptographic modules to enable external key wrapping.

## Practical Benefits for ServiceNow Customers

* Maintain authoritative control over encryption keys outside the ServiceNow infrastructure, improving security and compliance.
* Ensure sensitive data encryption keys are protected by your external key management system, reducing risks associated with internal key storage.
* Immediate response capability to security incidents via key revocation or rotation.
* Seamless integration with ServiceNow's Field Encryption Enterprise for flexible, role-based access to encrypted data.  
External Key Management Service (EKMS) enables you to integrate Field Encryption with your own external key management systems.
External Key Management Service (EKMS) enables you to maintain direct control over the encryption keys that protect your data within the ServiceNow platform. Rather than storing keys within the infrastructure, you can generate, store, and manage them in a dedicated key management system. This approach permits you to adopt cloud-based
enterprise services while maintaining control over your sensitive data.

You maintain authority over key lifecycle operations, including generation, rotation, and revocation allowing you to respond immediately to security events. This permits you to remove keys from your system, rendering your data
cryptographically inaccessible.

## Supported providers

Currently, EKMS for Field Encryption supports AWS Key Management Service (AWS KMS). Future releases will include support for additional key management providers.

## Key limitations

* Only one EKMS configuration can be created per instance.
* Multi-region keys are not supported.
* The AWS KMS key must be a symmetric key.

## How EKMS works

EKMS uses a key wrapping chain to secure data. See the EKMS key wrapping diagram below for a visual representation. When EKMS is configured:

1. A Key Encryption Key (KEK) is generated in your instance. For EKMS, this key is called an External Key Encryption Key (EKEK).
2. The EKEK is wrapped by an internal Instance Root Key (IRK), which is managed by your instance.
3. The IRK-wrapped EKEK is then wrapped again by your AWS KMS key, which you manage in AWS.
4. The wrapped EKEK is stored in the External Instance Keys table.
5. Data Encryption Keys (DEKs) for a cryptographic module are wrapped by the EKEK and stored in the module key table. The DEKs are what encrypts your field data.
6. Field data is encrypted using the cryptographic module's DEKs.

This architecture ensures that your instance never has direct access to decrypt the data without access to the external AWS key.

## Key status synchronization

A background job runs every 30 minutes to synchronize the AWS key status with your instance. This default frequency is configurable if you need a different synchronization interval. The synchronization ensures that key state changes
in AWS (enabled, disabled, pending deletion, deleted) are reflected in your instance.  
Important:  
AWS-deleted keys require a minimum of seven days before showing the deleted status, as this is controlled by AWS retention policies.

## Integration with Field Encryption Enterprise

EKMS integrates with Field Encryption Enterprise (FEE) functionality through cryptographic modules. Your AWS KMS key credentials and connection are managed on the EKMS Configuration page. On the Cryptographic Modules page, you
configure the module to use EKMS for external key wrapping. When you create an Encrypted Field Configuration (EFC), you specify which table and column should be encrypted, and which cryptographic module with external key wrapping
should be used for encryption.

EKMS integrates with Field Encryption Enterprise (FEE) through cryptographic modules. Cryptographic modules use your external AWS KMS key to wrap encryption keys, and Encrypted Field Configurations specify which data to encrypt. To use EKMS with FEE, you enable the External Wrap Key option on a cryptographic module and select your EKMS Configuration.

## Access control

Module Access Policies (MAPs) determine which user roles can view encrypted data in clear text. Users without the proper role assignments will not be able to decrypt and view the protected information, even if they have access to the
table.

## Get started {#external-key-management-service__section_vkz_rvv_f3c}

<br />

|-|-|-|
| [Configuring External Key Management Service](https://www.servicenow.com/docs/c3DYJWELAktpTlo_d~XFgA "Set up External Key Management Service (EKMS) to control the encryption of your ServiceNow data using your Amazon Web Service Key Management System (AWS KMS).") [](https://www.servicenow.com/docs/c3DYJWELAktpTlo_d~XFgA "Set up External Key Management Service (EKMS) to control the encryption of your ServiceNow data using your Amazon Web Service Key Management System (AWS KMS).") [Create and maintain Key Management components to customize and manage how cryptographic operations are performed on your ServiceNow instance.](https://www.servicenow.com/docs/c3DYJWELAktpTlo_d~XFgA "Set up External Key Management Service (EKMS) to control the encryption of your ServiceNow data using your Amazon Web Service Key Management System (AWS KMS).") | [External Key Management Service actions](https://www.servicenow.com/docs/ihmWVGyxEAAGrIUlIXIV_Q "Manage and maintain your External Key Management Service (EKMS) configuration after initial setup") [](https://www.servicenow.com/docs/ihmWVGyxEAAGrIUlIXIV_Q "Manage and maintain your External Key Management Service (EKMS) configuration after initial setup") [Use EKMS to manage , revoke or rotate keys to secure sensitive data with the most up-to-date encryption materials and life cycle operations.](https://www.servicenow.com/docs/ihmWVGyxEAAGrIUlIXIV_Q "Manage and maintain your External Key Management Service (EKMS) configuration after initial setup") |   |
|   |   |   |
[ ]

{#external-key-management-service__table_icw_nwv_f3c}

## Activation information {#external-key-management-service__section_qyq_v5v_f3c}

To activate the External Key Management Service, you must first purchase a subscription to either Platform Encryption or ServiceNow Vault.

The ServiceNow Platform Encryption subscription bundle is a group commercial entitlement that includes Field Encryption Enterprise and Cloud Encryption.

Field Encryption Enterprise is the unlimited license of Field Encryption Starter. Field Encryption Enterprise is available with the activation of the com.glide.field.encryption.enterprise plugin. For details, see [Encryption and Key Management subscription bundle](https://www.servicenow.com/docs/kgz4neM3TYVuTBJe8spPSg "With Key Management, Field Encryption is upgraded at no additional charge to include highly configurable encryption modules. You can also optionally upgrade to the unlimited-use license. Subscribe to the new encryption entitlement bundle, Platform Encryption, which includes Field Encryption Enterprise and Cloud Encryption.").

Once you've installed the Field Encryption Enterprise plugin, you then need to install the EKMS plugin called "Platform Encryption External Key Management". The plugin id is com.glide.encryption.external_kms. See [Activate External Key Management Service](https://www.servicenow.com/docs/4TWS5G5ZM2QHkLAusLKGtA "Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.") for more information.
* **[Configuring External Key Management Service](https://www.servicenow.com/docs/c3DYJWELAktpTlo_d~XFgA)**   
  Set up External Key Management Service (EKMS) to control the encryption of your ServiceNow data using your Amazon Web Service Key Management System (AWS KMS).
* **[Using External Key Management Service](https://www.servicenow.com/docs/ihmWVGyxEAAGrIUlIXIV_Q)**   
  Manage and maintain your External Key Management Service (EKMS) configuration after initial setup

