- Erste Schritte
- Best Practices
- Organisationsmodellierung im Orchestrator
- Beste Praktiken für die Automatisierung (Automation Best Practices)
- Optimieren von Unattended-Infrastruktur mithilfe von Maschinenvorlagen
- Organisieren von Ressourcen mit Tags
- Exportieren von Rastern im Hintergrund
- Durchsetzung der Governance der Integration Service-Verbindung auf Benutzerebene
- Mandant
- Über den Kontext „Mandant“
- Suche nach Ressourcen in einem Mandanten
- Verwaltung von Robotern
- Verbindung von Robotern mit Orchestrator
- Speicherung von Roboterzugangsdaten in CyberArk
- Speichern der Kennwörter von Unattended-Robotern im Azure Key Vault (schreibgeschützt)
- Speichern der Anmeldeinformationen von Unattended-Robotern im HashiCorp Vault (schreibgeschützt)
- Speichern der Anmeldeinformationen von Unattended-Robotern im AWS Secrets Manager (schreibgeschützt)
- Löschen von getrennten und nicht reagierenden Unattended-Sitzungen
- Roboter-Authentifizierung
- Roboter-Authentifizierung mit Client-Anmeldeinformationen
- Konfigurieren von Automatisierungsfunktionen
- Solutions (Lösungen)
- Audit
- Enforced encryption
- Einstellungen
- Registrierung
- Benachrichtigungen
- Events
- Anzeigen und Zugreifen auf Benachrichtigungen
- Anzeigen und Zugreifen auf E-Mail-Benachrichtigungen
- Es werden nur ungelesene Benachrichtigungen angezeigt
- Alle Benachrichtigungen als gelesen markieren
- Alle Benachrichtigungen löschen
- Löschen von Benachrichtigungen
- Abonnieren von Ereignissen
- Abbestellen von Ereignissen
- Ordnerkontext
- Prozesse
- Jobs
- Apps
- Auslöser
- Protokolle
- Überwachung
- Indizes
- Warteschlangen
- Assets
- Über Assets
- Verwalten von Assets in Orchestrator
- Verwalten von Assets in Studio
- Speichern von Assets im Azure Key Vault (schreibgeschützt)
- Speichern von Assets im HashiCorp Vault (schreibgeschützt)
- Speichern von Assets im AWS Secrets Manager (schreibgeschützt)
- Speichern von Assets in Google Secret Manager (schreibgeschützt)
- Verbindungen
- Geschäftsregeln
- Speicher-Buckets
- Agent-Gateway
- Testverfahren in Orchestrator
- Ressourcenkatalogdienst
- Integrationen
- Fehlersuche und ‑behebung
Enforced encryption
Enforced encryption in Orchestrator, covering which job, robot log, queue, and storage bucket data is encrypted at rest and how encryption affects search, reporting, and exported data.
Enforced encryption is a tenant-level configuration that makes Orchestrator store sensitive automation data encrypted at rest. When enforced encryption is enabled, Orchestrator encrypts job data, robot logs, queue items, and Orchestrator storage bucket content, and the option to store queues and Orchestrator storage buckets unencrypted is no longer available.
Enforced encryption adds application-level encryption (ALE) on top of the encryption that UiPath applies to all data: TLS 1.2 or higher for data in transit, and Transparent Data Encryption (TDE) with AES 256-bit encryption for data at rest. With enforced encryption, Orchestrator encrypts the data before storing it, using a key from the key management service (KMS).
For details, see Encryption and Customer-managed keys.
Verfügbarkeit
Enforced encryption is available in Automation Cloud and Test Cloud for organizations on the Enterprise plan (Flex) or the Standard or Enterprise plan (Unified Pricing).
Enforced encryption is enabled on request by your technical account manager or UiPath Support, not from Orchestrator.
After enforced encryption is enabled, Orchestrator displays no setting for it.
Verschlüsselte Daten
The following table lists the data that Orchestrator encrypts when enforced encryption is enabled.
| Ressource | Encrypted fields |
|---|---|
| Jobs | Input arguments, Output arguments, Info, Environment variables |
| Job events | Information (Info) |
| Roboter-Protokolle | All fields, except the fields listed in Unencrypted robot log fields |
| Warteschlangenelemente | Specific Data, Output Data, and the following processing exception fields: Reason, Details, Associated Image File Path. For the fields that stay unencrypted, see Unencrypted queue item fields. |
| Orchestrator-Speicher | All content: Buckets, Packages, Job Attachments, Videos, Screenshots, Exports, Knowledge Bundles, Retention archives, Business rules |
Unencrypted robot log fields
The following robot log fields are not encrypted:
machineNamemachineIdwindowsIdentityrobotNameprocessNameprocessVersionjobIdfilenameinitiatedBytotalExecutionTimeInSecondslevellogTypeorganizationUnitIdqueueNametransactionIdtransactionStatetransactionStatustransactionExecutionTimeprocessingExceptionTypequeueItemPriorityqueueItemReviewStatus
Unencrypted queue item fields
The following queue item data is not encrypted:
AnalyticsDataReferenceProgressProcessingExceptionTypeProcessingExceptionCreationTime- Status, date, and key fields
- Queue item comments
- Queue item events. These contain no queue item payload data.
Queues and storage buckets
Queues and Orchestrator storage buckets have a Store in encrypted format option that lets you choose whether their data is encrypted.
With enforced encryption, this choice is no longer available, and all queues and Orchestrator storage buckets are encrypted automatically. The missing choice when creating a queue or an Orchestrator storage bucket is the only visible effect of enforced encryption in Orchestrator.
Enforced encryption applies only to storage buckets that use the Orchestrator storage provider. Storage buckets that use an external provider, such as Azure Storage, Amazon S3, or Google Cloud Storage, are not affected.
Einschränkungen
Enforced encryption affects how you work with the encrypted fields:
- Search: Free-text search in robot logs and queue items works only on unencrypted fields. Encrypted fields, listed in Encrypted data, can't be searched.
- UiPath Insights: Encrypted data remains encrypted in UiPath Insights, so the encrypted fields are not available for reporting.
- Exported data: Orchestrator decrypts data when it leaves Orchestrator. Exported robot logs and webhook payloads contain decrypted data, so enforced encryption does not protect data after export.
- Audit logs: If enforced encryption has ever been enabled for a tenant, audit log entries for that tenant don't include job input arguments, output arguments, info, or environment variables.
- Healing Agent: Healing Agent is not available for tenants with enforced encryption. For details, see Healing Agent documentation.
For more information about encryption across UiPath services, see Encryption.