Activate External Key Management Service

  • Versão de lançamento: Australia
  • Atualizado 12 de mar. de 2026
  • 1 min. de leitura
  • Install the External Key Management Service (EKMS) plugin and configure user permissions to enable external key management functionality.

    Antes de Iniciar

    Roles required: admin, security_admin, and sn_kmf.cryptographic_manager

    Dependencies:

    The following plugins need to be already installed on your environment:
    • Key Management Framework Scoped App
    • Field Encryption Enterprise

    Por Que e Quando Desempenhar Esta Tarefa

    Activating EKMS installs the necessary components to encrypt ServiceNow data with external keys managed in AWS Key Management Service.

    Procedimento

    1. Navigate to All > System Definition > Plugins.
    2. Under Search your licensed applications and plugins, search for Platform Encryption External Key Management.

      The search should reveal the plugin. If you purchase a subscription for External Key Management Service, you can also see this plugin available.

      Importante:
      To activate External Key Management Service, you must first purchase a subscription to the service and its dependencies: Field Encryption Enterprise and Key Management Framework Scoped App. Your account manager can arrange to have the plugin activated on your organization’s production and non-production instances.
    3. Select Install
      Nota:
      When domain separation and delegated admin are enabled in an instance, the administrative user must be in the global domain. Otherwise, the following error appears: Application installation is unavailable because another operation is running: Plugin Activation for <plugin name>.

    Resultado

    The EKMS plugin is now installed and activated. You can proceed to configure your external key integration.

    O que Fazer Depois

    Next steps:

    • Set up AWS Key Management Service access
    • Configure the EKMS key definition in ServiceNow