Enable encryption on standard properties

Some organizations have requirements to encrypt phone fields in the Salesforce instance. This requires some changes in the CCAI Platform portal to allow searching for these phone numbers. For information about conducting searches for encrypted phone fields, see Enable exact search queries for encrypted phone fields.

Permissions

  • CC_Agent_App must be 1.38+ to enable encryption on standard properties.

  • Admin must have Manage Encryption Keys, Customize Application, View Setup and Configuration, & Manage Certificates permissions in their role.

Enable encryption

To enable encryption in the Salesforce platform, follow these steps:

  1. To create a new tenant secret, do the following. This is required to create a deterministic tenant secret.

    1. Go to Setup > Key Management.

    2. Click Generate Tenant Secret.

  2. Go to Encryption Settings > Deterministic Encryption, and click the toggle to the on position.

  3. To create a new Deterministic Tenant Secret, do the following:

    1. Go to Setup > Key Management.

    2. Go to the Fields (Deterministic) tab.

    3. Click Generate Tenant Secret.

  4. From Setup, in the Quick Find field, enter Encryption Settings, and then select Encryption Settings. Only new data is affected by this setting change. To apply these settings retroactively, see Synchronize Your Data Encryption with the Background Encryption Service.

  5. Update settings to encrypt phone fields on the contact types.

  6. In the phone field, select Deterministic. Probabilistic won't work with exact searches. Exact searches are required to search for encrypted phone numbers.

  7. Click Apply. An email is generated that contains a summary of the encryption settings. If any fields are invalid an explanation is included.

Example email

The following is an example email.

Encryption is now enabled on one or more fields.

These fields use deterministic encryption:
Contact: Phone, Home Phone, Other Phone

Salesforce Shield Platform Encryption