Revoke dedicated encryption keys

Last updated on Aug 3, 2026

Revoke your organization's encryption key to restrict access to encrypted content in the Admin Console.

When you revoke a dedicated encryption key, user access to all content encrypted with that key is immediately restricted. Revoking a key provides critical protection in security-sensitive situations.

When you revoke the key, users can still browse files and folders and view file attributes, but they cannot open, download, or upload content.

Before you begin

Ensure you have System Admin permissions in the Adobe Admin Console and that your organization uses dedicated encryption keys (this option is unavailable for standard encryption).

Revoke the encryption key

Sign in to the Adobe Admin Console and navigate to Settings > Identity > Encryption Settings.

On the Encryption Settings page, disable the dedicated encryption key.

Select Revoke Encryption Key
Disable the dedicated encryption key.

Select Revoke to confirm.

A success message appears.

Restore access to encrypted content

To restore user access to content after revoking the encryption key, re-enable the encryption key from the same Encryption Settings page in the Admin Console. The previously encrypted content will become accessible again once you confirm re-enabling the key.