Dedicated encryption keys FAQ

Last updated on Aug 3, 2026

Get answers to common questions about dedicated encryption keys for your organization.

These questions typically arise when evaluating or managing dedicated encryption for your organization's content. Questions cover the scope of encryption, key management, and data access implications.

Yes. Adobe is updating dedicated encryption from directory-level to organization-level. When you enable encryption in the Admin Console, all users' assets in the organization are encrypted.

Yes, the Admin Console displays a notification when existing content has been encrypted.

Yes. You can revoke encryption at the organization level from the Admin Console. If you revoke the key, users will no longer be able to access encrypted content.

Re-enable the encryption key from the Admin Console to restore access to content whose encryption key has been revoked.

Yes, users can browse files, but they cannot access their contents when the encryption key is disabled.

The sync operation fails if the encryption key is revoked while a file sync operation is in progress.

No. Once you enable a dedicated encryption key, you cannot revert to using standard encryption keys.

Metadata, Lightroom photos, Adobe Color service data, Behance and Adobe Fonts data, Experience Cloud data, application preferences, and basic user account information are not encrypted using the dedicated encryption key.

Visit Adobe Trust Center for detailed security information.