Skip to content
Release: Australia · Updated: 2026-03-12 · Official documentation · View source

Module lifecycle policy exceptions for Field Encryption

Use module lifecycle policy exceptions to customize the lifecycle of your module keys.

Before you begin

Role required: sn_kmf.admin or sn_kmf.cryptographic_manager

About this task

Module lifecycle policy exceptions change the lifecycle policy of Field Encryption modules from the standard Instance-level lifecycle policy. For example, if you've configured symmetric keys to be limited to one year at the instance level, you can create a module lifecycle policy exception for a specific Field Encryption module to allow its key to remain active for two years.

Procedure

  1. Navigate to All > System Security > Field Encryption > Field Encryption Modules.

  2. Select the field encryption module record that requires a module lifecycle policy exception.

  3. In the field encryption module record, select New in the Module Policy Exceptions related list.

  4. In the key lifecycle policy form, fill in the fields as needed.

    FieldDescription
    Crypto ModuleDisplays the name of the field encryption module that will use this policy exception.
    Applies ToThe specified key is auto populated.
    Key TypeSelect the key type. Exception policies are related to a specific key. Multiple exception policies can be created per Field Encryption Module.
    Policy ConditionCreate qualifying conditions from the drop-down menu and complete the additional constraint criteria.
    ResultSelect Reject to reject use of the key or Track to allow use of it when the criteria are met.
  5. Select Submit.

Parent Topic:Configuring Field Encryption