---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Exploring Field Encryption

# Exploring Field Encryption {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 2 Minuten Lesedauer

Learn the details of Field Encryption Starter and Field Encryption Enterprise

## Encryption-backed access control {#exploring-fe__cf-exploring-parent-overview}

By default, Field Encryption blocks all users, scripts, and system processes from accessing encrypted data. However, Field Encryption has an access control feature that is used in combination with, but also separate from, Access Control Lists (ACLs) to ensure only the correct users, scripts, or system processes can access
encrypted data.

You can configure Field Encryption access control feature through a combination of Field Encryption Modules, Encrypted Field Configurations, and Module Access Policies. The next image shows how these three components work together.

Module Access Policies (shown in the next image) are how users, scripts, or system processes can be authorized to access encrypted data (but by default, the encrypted data is locked down from any access in the
instance).

## Differences between Field Encryption Starter and Field Encryption Enterprise {#exploring-fe__section_bbm_xhn_b2c}

The feature-set is different between Field Encryption Starter and Field Encryption Enterprise.
{#exploring-fe__table_uk2_b3n_b2c__entry__3}

| Feature | Field Encryption Starter | Field Encryption Enterprise |
|-|-|-|
| Number of encrypted fields | Up to 5 encrypted fields | No restriction on number of encrypted fields |
| Attachment encryption | No | Yes |
| Key management | None (Contact ServiceNow Support for key rotation) | Manage keys from your instance with no involvement from ServiceNow Support |
| Supported data types | All supported data types | All supported data types |
| Number of Field Encryption Modules | No restriction | No restriction |
| Number of Module Access Policies | No restriction | No restriction |
[ ]

{#exploring-fe__table_uk2_b3n_b2c}

## Field Encryption users {#exploring-fe__cf-exploring-parent-users}

{#exploring-fe__table_k3r_dhn_b2c__entry__2}

| User | Description |
|-|-|
| Key Management Framework (KMF)Admin or KMF Cryptographic Manager | These roles are used to configure elements of Field Encryption. * Field Encryption modules and module keys * Cryptographic Specifications * Module life-cycle policies * Encrypted field configurations for fields and attachments * Module Access Policies (MAPs) * Configures, wraps, and uploads customer supplied keys (for Field Encryption Enterprise) * Configures Access Observer and review Access Observer logs. * Schedule mass encryption, decryption, or re-keying {#exploring-fe__ul_g1h_mvn_b2c} |
| KMF Cryptographic Operator | Configures properties for customer supplied keys |
[Tabelle : 1. Users]

{#exploring-fe__table_k3r_dhn_b2c}

## Field Encryption and record history {#exploring-fe__section_pmv_bgy_q2c}

Changes to fields encrypted with Field Encryption are not tracked in the activity stream for the record or in the record history \[sys_history_set\] table.

## Encryption on system tables {#exploring-fe__section_ph2_xjb_sgc}

Field Encryption currently doesn't support the encryption of fields and attachments of system tables (tables that begin with sys_).

## What to explore next {#exploring-fe__cf-exploring-parent-links}

To learn more about configuring and using Field Encryption, see:

* [Configuring Field Encryption](https://servicenow-prod.fluidtopics.net/FuhiU1TmFY_639oakK5t1Q "Learn how to activate and configure Field Encryption and manage migration from Encryption Support.")
* [Using Field Encryption](https://servicenow-prod.fluidtopics.net/HTtt24lNh5S9x24kvKiVaQ "Use Field Encryption to manage access to encrypted data on your instances.")
{#exploring-fe__ul_o3r_dhn_b2c}
* **[Field Encryption Enterprise](https://servicenow-prod.fluidtopics.net/EBdZ47_FhiYcUtkaTDXBXg)**   
  Field Encryption Enterprise uses the Key Management Framework (KMF) to enable you to customize and manage how fields and attachments are encrypted and decrypted on your instance. A subscription is required to use Field Encryption Enterprise.

