Bring Your Own Key (BYOK) for Adaptive Planning
We now enable you to use your own AWS customer managed key (CMK) to encrypt your Adaptive Planning tenant database.
Production Date: 2025-03-15
Business Benefits
- Provides you greater control over your tenanted data stored in Adaptive Planning databases.
- Enhances security and enables you to protect your data with your own encryption keys.
- Aligns your data security practices with regulatory standards.
- Simplifies administration within your AWS environment.
Changes
Customers can now import, manage, and use their own encryption keys in their AWS Key Management Service (KMS) instance for encrypting and decrypting data within Adaptive Planning.
What Do I Need to Do?
Your Named Support Contact (NSC) must contact Workday support to enable the feature.
- Purchase the BYOK SKU.
- In the Workday Community, create a product support request under Adaptive Planning, Security & Administration.
- Set the subject as "Request for BYOK Onboarding".
- Provide these details using the support request record:
- As the key administrator, create the key for the primary region in your AWS KMS instance.
- Grant the Workday Adaptive Planning production AWS account (ID: 244702149041) usage access to the new key. Use the policy applied to the key to do this.
- Provide the Amazon Resource Name (ARN) to the key including the CMK ARN for each key (arn:aws:kms:<Region>:<ThirdPartyAWSAccountID>:key/<CMKID>).
- Key contact information for the Adaptive Planning Cloud Ops team for enabling the BYOK feature.
What Happens If I Do Nothing?
If you don’t purchase the BYOK SKU, Adaptive Planning will continue to manage your keys for your encrypted data at rest.