---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Set up Module Access Policies

# Set up Module Access Policies {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Define which user roles can view encrypted data in clear text by configuring module access policies for External Key Management Service (EKMS).

## Vorbereitungen

Role required: admin  
Confirm that you have:

* [Created a cryptographic module with external key wrapping enabled](https://servicenow-prod.fluidtopics.net/ljQ3vNp3pALVUrun2sAIIw "Configure your external encryption key to use in External Key Management Service (EKMS).")
* [Created an Encrypted Field Configuration](https://servicenow-prod.fluidtopics.net/bXF45FU2G8xLBqmkMqrRyQ "Configure specific table fields to be encrypted using your External Key Management Service (EKMS) cryptographic module with external Amazon Web Services Key Management System (AWS KMS) key wrapping.")
{#ekms-set-up-maps__ul_ilj_ljq_33c}

## Prozedur

1. Navigate to AllSystem SecurityField EncryptionField Encryption EnterpriseConfigurationsAccess Policies.  
   Hinweis:  
   For additional information, refer to [Configure module access policies for Field Encryption](https://servicenow-prod.fluidtopics.net/b5Fi_fL46STNIHpPr4rI2Q "Create module access policies to decide which users and scripts can access data encrypted by a cryptographic module.").
2. Select Configure.
3. Complete the Module Access Policy (MAP) form.  
   {#ekms-set-up-maps__table_w2n_qfy_j3c__entry__2}

   | Field | Description |
   |-|-|
   | Policy name | Enter a name for the policy. |
   | Type |   |
   | Target scope | Field is visible as an identifier for the Scope type. Refers to the functionality for the policy. Select the applications from the search menu. |
   | Specify purpose | Optional.  Enable  to  display  the  Crypto  Spec  field  on  the  form.  Enable this option to configure granular operations, such as some users being able to encrypt, but not decrypt.  |
   | Application | The  Application scope  is  auto-populated  by  your  current scope.  |
   | Active | Select to activate the policy. |
   | Result | Select one of the following: * **StrictReject** rejects access under all circumstances. * **Reject** rejects users with the **Target Role** or **Target Scope** from accessing this cryptographic module unless another policy grants them access. * **Track** to permit access and monitor use of the module. {#ekms-set-up-maps__create-module-access-policy_ul_a5d_jr4_tnb} |
   [Tabelle : 1. MAP Form]

   {#ekms-set-up-maps__table_w2n_qfy_j3c}

## Ergebnisse

The Module Access Policy for the script is available in the system.

Next steps:

* [Test an external key definition](https://servicenow-prod.fluidtopics.net/F6NOlVR3x7kGZrGmUHku~Q "Test your external encryption key to use in External Key Management Service (EKMS).")
* [Learn how to change the status of an AWS KMS Key](https://servicenow-prod.fluidtopics.net/EoaP6xop_9tey6bLq7Skvw "Modify the status of your Amazon Web Services Key Management System (AWS KMS) key and synchronize the status with your ServiceNow instance.")
{#ekms-set-up-maps__ul_vln_5zs_k3c}

