Set up BYOK encryption
Enrollment in BYOK encryption is no longer available. You can opt to enroll in Customer-managed keys (CMK) encryption, which offers enhanced control over encryption keys for safeguarding your Atlassian Cloud data. Existing BYOK customers will eventually be migrated to CMK.
Who can do this? |
Adding a BYOK-encrypted Atlassian app
Before you can set up CMK-enabled Atlassian apps, you need to:
Set up your AWS account
Create the IAM role
If you don’t already have these set up, you will instead need to enroll in Customer managed keys (CMK) encryption. See What is CMK encryption?
Currently, we don’t support migration of data between locations.
You can’t convert a BYOK-encrypted app into a non-BYOK app (an app with data encrypted with Atlassian-managed keys).
When you add an Atlassian app, you have the choice of using an Atlassian managed key or BYOK, giving you greater control over encryption keys.
To set up a BYOK-enabled Atlassian app:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Apps, then Atlassian apps
Select Add app to display the Atlassian app available.
From the list, find the Atlassian Enterprise app you wish to add, and select Add app.
Select whether you’d like to use a new or an existing site, then enter (or select) its URL.
Select Next.
From the Encryption dropdown, select Bring your own key (BYOK) encryption.
Select Add.
Provisioning of your Atlassian app will now begin. Learn what data is managed with BYOK encryption
View your BYOK-encrypted apps
To view your BYOK-encrypted apps:
Go to Atlassian Administration. Select your organization if you have more than one.
Select Security, then Data protection, then Encryption.
Was this helpful?