---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Role requirements for Field Encryption

# Role requirements for Field Encryption {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Learn about the roles required to configure Field Encryption.
Managing requires the following roles. Since is based on the Key Management Framework, there are roles common to both.

* Admin
* security_admin
* sn_kmf.admin
* sn_kmf.cryptographic manager

{#fe-roles__ul_k2q_qw4_22c}

For complete details on details on roles, see [Roles installed with Key Management Framework](https://servicenow-prod.fluidtopics.net/aruIC5O_pblgIxuOxBeY2A#kmf-roles "The Key Management Framework (KMF) introduces specific roles for cryptographic module and key management-related configurations.").

## Admin and Security Admin {#fe-roles__section_icm_3x4_22c}

Users must have the admin role to elevate to the Security Admin role. You need the Security Admin role to perform high Security Tasks, such as configuring encrypted field configurations and configuring Access Observer.

Admins can elevate to Security admin using this procedure.

1. Select on your profile picture at the top right of the screen.
2. In the drop-down menu, select Elevate Role.
3. Select Security Admin.
4. Select Save.
{#fe-roles__ol_oph_x1p_22c}

## KMF Admin {#fe-roles__section_wdt_3x4_22c}

Users with the Admin role can assign users to the KMF admin role using this process:

1. Navigate to AllSystem SecurityKey Management Administration.
2. From the Available Users list, move a user who needs the KMF Admin role over to the Selected User(s) list.
3. Select Save.

{#fe-roles__ol_y4t_jy4_22c}  
Wichtig:  
For help prevent security issues, avoid granting the KMF Admin role to more than one users. Avoid assigning this role to users when more specialized roles are available.

## KMF Cryptographic Manager {#fe-roles__section_mt2_qz4_22c}

Users with the KMF Cryptographic Manager role can create and update operations on cryptographic modules and module access policies. KMF cryptographic managers can also perform key management and life cycle operations.

Use the following process to assign this role to a user.

1. Navigate to AllSystem SecurityUsers.
2. Select a user that needs to configure Field Encryption.
3. In the Roles related list, select Edit.
4. Search for <kbd class="ph userinput">sn_kmf.cryptographic manager</kbd> and add the role the selected user.
5. Select Save.
{#fe-roles__ol_t25_sz4_22c}

