---
sourceDocument: Australia Platform security
sourceDocumentLink: https://servicenow-prod.fluidtopics.net/r/de-DE/platform-security

 Release :

    - australia

ft:locale :

    - de-DE

ft:publication_title :

    - Australia Platform security

ft:clusterId :

    - psec

bundleId :

    - psec

workflow :

    - Platform


---

# Migrating to Field Encryption Enterprise

# Migrating to Field Encryption Enterprise {#ariaid-title1}

* Freigeben Version: Australia
* 
* Aktualisiert 12. März 2026
* 
* ![](https://www.servicenow.com/docs/portal-asset/ico-clock) 1 Minute Lesedauer

Scheduled jobs migrate your keys and encrypted data from Encryption Support to Field Encryption Enterprise.
You can review the scheduled jobs by navigating to System SecurityHigh Security SettingsSecurity Jobs:  
* autoKeyMigration: Migrates encryption context keys to Key Management Framework (KMF) cryptographic module keys.
* autoDataMigration: Migrates data that you already encrypted to use the KMF cryptographic module key.
{#migration-to-platform-encryption__ul_d24_wfg_14b}

You can modify when these scheduled jobs run, and can pause or restart them at any time.  
Verify that the encrypted field configurations are using your newly migrated module keys by navigating to System SecurityField EncryptionEncrypted Field Configurations. Look for the following items:

* The Method field is Single Module.
* The Crypto module field is populated with the name of the cryptographic module that the system automatically creates. You can review that module and the module access policy, both of which are active and published.
{#migration-to-platform-encryption__ul_iw5_2c4_d4b}

## Field Encryption Enterprise and system clones {#migration-to-platform-encryption__section_jxz_cqx_fvb}

If Field Encryption Enterprise is installed on your instance, a new field encryption module encryption key is automatically generated on the target clone instance as a part of clone process. These keys are
generated for all modules to which the user has access, and that does not have a key already.

Because of this, field encryption modules on the target clone instance may have two module
encryption keys present:

* An active module encryption key. This is the new key generated after clone, as long as the module is accessible to the user and has no prior keys.
* A deactivated encryption module key (from the automated key exchange transferThe
  active module encryption key is used to encrypt inserted data as needed on the target
  clone instance. The deactivated module is used to decrypt existing data that was cloned
  over as part of the system clone.

  To use a single key to decrypt and encrypt all
  data, you can run a module rekeying job. For more information about module rekeying
  jobs, see [Schedule mass encryption,
  decryption, and rekeying jobs](https://servicenow-prod.fluidtopics.net/zFqhMZZDbYGjie6eyZ9avA "Schedule encryption, decryption, and rekeying jobs to run at a time that is best for your instance.").
{#migration-to-platform-encryption__ul_ayc_prx_fvb}
* **[Field Encryption migration status page](https://servicenow-prod.fluidtopics.net/7wUkqYcUrEjYl0QyDP3s3w)**   
  Use the migration status page to track the migration of encryption contexts to encryption modules.

