Generate a Search Index Data Encryption Key

In Hyperforce orgs, create the search index encryption data encryption key (DEK) from the Key Management page in Setup. DEKs are secured with Salesforce root keys.
Available in both Lightning Experience and Salesforce Classic (not available in all orgs).
Available as an add-on subscription to Hyperforce orgs in: Enterprise, Performance, and Unlimited Editions. Requires purchasing Salesforce Shield. Available in Developer Edition at no charge.

User Permissions Needed
To generate, destroy, export, import, upload, and configure Shield Platform Encryption key material: Manage Encryption Keys

Using Setup is the only way to manage Search Index DEKs. You can’t manage them using Apex.

Note

  1. From Setup, in the Quick Find box, enter Platform Encryption, and then select Key Management.
  2. Select the Search Index tab. Then click Generate DEK.
    The new DEK is generated. This DEK is used to encrypt all new data in the search index, which builds dynamically as it captures new search data.

    Periodically, more than one iteration of your DEK is needed to encrypt search indexes as they’re built. Automatically generated DEK iterations are identifiable by the Automated Process value listed in the Created By column. These iterations of your DEK share a version number.

    When you generate another DEK, all DEKs of the previous version are archived.

    Key Inventory and Management Setup page, showing Search Index keys