Step 4. Edit Encryption Settings

Veeam Data Cloud allows you to encrypt backed-up fields and files using data key that is enciphered with either a Veeam Data Cloud master key or an Amazon Web Services Key Management Service (AWS KMS) master key. By default, encryption is enabled for all object fields and file types with a Veeam Data Cloud master key.

At the Data Encryption step of the wizard, you can configure the following encryption settings:

  1. In the Encryption settings section, choose whether you want to encrypt specific object fields, file types or both. If you do not select any object fields or file types, this data will not be encrypted.

For an object field to be displayed in the list of available fields, both the object and the field must be added to the backup scope specified at the previous step. For a file type to be displayed in the list of available file types, it must be included in the list of backup files and attachments specified at at the previous step.

Important

  • Veeam Data Cloud supports encryption of the following field types only: Text, TextArea, Text Area (Long), Text (Encrypted), Address, Number, Email, Text Formula, Number Formula, Percent Formula, Currency Formula, Geolocation. For more information on Salesforce field types, see Salesforce Documentation.
  • If an object record that you want to back up contains fields that have been specified as filtering conditions in an archival policy, you will not be able to encrypt these fields. Edit the filtering criteria settings of the archival policy — and then modify the backup policy settings to encrypt these fields.
  1. In the Encryption key section, choose whether you want to encrypt backed-up data using an AWS master key or a master key generated by Veeam Data Cloud. If you want to use an AWS master key, you must also select the region to which the key belongs.

For an AWS master key to be displayed in the list of available keys, it must be added to the selected region in an AWS account as described in AWS Documentation, and this account must be connected to Veeam Data Cloud as described in section Configuring Encryption Settings. If you have not connected the AWS account beforehand, you can do it without closing the Add Backup Policy window. To do that, click Add AWS KMS Connection and follow the instructions provided in section Adding AWS KMS Connections.

You must not remove the AWS master key from the related AWS account. Otherwise, you will not be able to decrypt and restore backed-up data.

 

Editing Encryption Settings