Skip to content
Release: Australia · Updated: 2026-04-02 · Official documentation · View source

Set up Module Access Policies

Configure module access policies in External Key Management Service (EKMS) to control who can view encrypted data in clear text.

Before you begin

Role required: sn_kmf.admin or sn_kmf.cryptographic_manager

Confirm that you have:

Procedure

  1. Navigate to All > System Security > Field Encryption > Field Encryption Experience > Configurations > Access Policies.

    Note: For additional information, refer to Configure module access policies for Field Encryption.

  2. Select Create New.

  3. Select Configure.

  4. Complete the Module Access Policy (MAP) form.

FieldDescription
Policy nameEnter a name for the policy.
TypeDecide who or what should have access to this MAP to encrypt or decrypt data.- Scope- Anything within the specified Application Scope has access to this MAP. - Role- Only users with the specific role can access this MAP. - Script- Ensure a specified script can access this MAP. - System Access- Allows processes running in “System Context” access to this MAP. - Resource Exchange- Allows for the Resource Exchange feature access to this MAP. For more information on how these different types of MAP work, see Exploring Field Encryption.
Target scopeField is visible as an identifier for the Scope type. Refers to the functionality of the policy. Select the applications from the search menu.
Specify purposeOptional.  Enable  to  display  the  Crypto  Spec  field  on  the  form.  Enable this option to configure granular operations, such as some users being able to encrypt, but not decrypt. 
ApplicationThe  Application scope  is  auto-populated  by  your  current scope. 
ActiveSelect to activate the policy.
ResultSelect one of the following:- StrictReject rejects access under all circumstances. - Reject rejects users with the Target Role or Target Scope from accessing this cryptographic module unless another policy grants them access. - Track to permit access and monitor use of the module.
Image omitted: ekms-create-map-track-ui.png
Example of completed MAP form.

Result

The Module Access Policy for the script is available in the system.

Next steps:

Parent Topic:Configuring External Key Management Service