Set up dedicated encryption keys

Last updated on Aug 3, 2026

Configure organization-level encryption in the Admin Console to secure user assets using Adobe-generated keys.

This procedure enables dedicated-key encryption for all users and content. Once enabled, dedicated encryption can’t be reverted to standard encryption. You can revoke and re-enable the key if necessary.

Enterprise plans with storage and services include encryption keys. If your current plan does not include these features, contact your Adobe Account Manager to upgrade.

Before you begin

To enable dedicated encryption keys, you require:

  • Enterprise or Federated ID setup
  • System administrator role
  • Enterprise plan with storage and services

Enable encryption for your organization

Sign in to the Admin Console with System Administrator credentials.

Navigate to Settings > Identity > Encryption Settings.

On the Encryption Settings page, enable encryption.

Review the confirmation message describing the impact of enabling encryption.

Select Enable to confirm and activate the dedicated encryption key for your organization.

The Admin Console confirms that dedicated key encryption is enabled. A progress indicator appears if the system is still encrypting existing assets. The encryption process runs in the background.

Tip

Monitor the Encryption Settings page to track the status of asset encryption for your organization. The Admin Console displays notifications if encryption fails for any assets.