---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Configure an external key definition

# Configure an external key definition {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Configure your external encryption key to use in External Key Management Service (EKMS).

## Vorbereitungen

Roles required: admin, security_admin, and sn_kmf.cryptographic_manager  
Hinweis:  
To configure EKMS, verify that you have an enabled key with your external key management provider and the configured user has the necessary permissions to use the key.  
The user must have permissions to run the following AWS KMS API operations:

* kms:DescribeKey
* kms:Encrypt
* kms:Decrypt
{#ekms-configure-external-key-definition__ul_dtn_fsf_m3c}

## Prozedur

1. Navigate to AllSystem SecurityField EncryptionEKMS ConfigurationsNew.
2. On the form, fill in the fields.  
   {#ekms-configure-external-key-definition__table_t3n_lcq_g3c__entry__2}

   | Field | Description |
   |-|-|
   | Application | Automatically populated with Global. |
   | Cloud KMS Provider | Automatically populated with AWS. |
   | EKMS Integration Name | Choose a name for the key definition. This name is referenced when running scripts. |
   | Key Region | Enter the key region associated with your external key. |
   | External Key Identifier | Enter the Amazon Resource Name (AWS ARN) for your external key. |
   | Primary Region URL | Enter the unique Primary Regional URL that begins with KMS. Example: https://kms.\[key region\]_amazonaws.com. |
   | KMS Credentials Access Key | Enter the key management service (KMS) for your credentialed AWS user. |
   | KMS Credentials Secret Key | Enter the secret key for your credentialed AWS user. |
   [ ]

   {#ekms-configure-external-key-definition__table_t3n_lcq_g3c}
3. Select Submit.

## Ergebnisse

The external key definition is configured.

## Nächste Maßnahme

Next steps:

* [Create a cryptographic module with external key wrapping](https://servicenow-prod.fluidtopics.net/721K8IKp~YSc5rn8w7iqDw "Create a cryptographic module that uses external Amazon Web Services Key Management System (AWS KMS) key wrapping to encrypt ServiceNow data.")
* [Create encrypted field configurations to specify which tables and columns to encrypt](https://servicenow-prod.fluidtopics.net/bXF45FU2G8xLBqmkMqrRyQ "Configure specific table fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.")
* [Set up module access policies to control who can view the encrypted data](https://servicenow-prod.fluidtopics.net/nBRMQAtk04wAF4Jhfpr2uw "Define which user roles can view encrypted data in clear text by configuring module access policies for External Key Management Service (EKMS).")
{#ekms-configure-external-key-definition__ul_e1f_dch_g3c}

