> For the complete documentation index, see [llms.txt](https://help.verkada.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.verkada.com/command/ja/sekyuriti/enterprise-controlled-encryption/enable-enterprise-controlled-encryption.md).

# エンタープライズ制御暗号化を有効にする

{% hint style="info" %}
参照 [Enterprise Controlled Encryption (ECE) の概要](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf) を参照してください。
{% endhint %}

***

## 前提条件

### シングルサインオン OIDC を設定する

Verkada は現在、シングルサインオンの OIDC で利用できる IDプロバイダ として、Okta、Microsoft Entra ID (Azure AD)、および Google Workspace のみをサポートしています。設定ガイドは次を参照してください:

* [Okta](/command/ja/sekyuriti/identity-providers/okta.md)
* [Microsoft Entra ID](/command/ja/sekyuriti/identity-providers/microsoft-entra-id.md)
* [Google Workspace](/command/ja/sekyuriti/identity-providers/google-workspace.md)

{% hint style="danger" %}
ECE を有効にするには、オーガナイゼーション' で OIDC SSO を有効にする必要があります。
{% endhint %}

### Command Mobile アプリを更新する

オーガナイゼーション' 内のすべてのユーザーに、Verkada Command Mobile アプリを更新するよう依頼してください。自動更新が無効でない限り、アプリは自動的に更新されます。

* iOS: [Verkada Command](https://apps.apple.com/us/app/verkada-command/id1157022527)
* Android: [Verkada Command](https://play.google.com/store/apps/details?id=com.verkada.android\&hl=en\&gl=US)

更新する **必要は** Verkada Pass アプリはありません。

***

## ECE を有効にする

{% stepper %}
{% step %}
**Verkada Command で、All Products > Admin に移動します。**
{% endstep %}

{% step %}
**左側のナビゲーションで、\[ログイン & アクセス] > \[Enterprise Controlled Encryption] を選択します。**
{% endstep %}

{% step %}
**\[開始する] をクリックします。**
{% endstep %}

{% step %}
**\[キーを生成] の下で:**

a. クリック **キーを生成**\
b. 暗号化キーをダウンロード\
c. [暗号化キーを IDプロバイダ に追加する](#add-encryption-key-to-identity-provider)\
d. クリック **続行**
{% endstep %}

{% step %}
**\[検証] の下で:**

a. クリック **ログアウトしてテスト**\
b. 成功すると、このページにリダイレクトされます\
c. クリック **続行**
{% endstep %}

{% step %}
**\[デバイスを登録] の下で:**

a. クリック **デバイスを選択** し、ECE に登録するデバイスを選択します\
b. クリック **デバイスを登録**

{% hint style="info" %}
おすすめは **すべてのデバイスを選択** して、フリート全体に追加のセキュリティとデータ保護を確保することです。
{% endhint %}
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
暗号化キーは一度だけ生成する必要があります。このキーを使用して OIDC プロバイダ にマッピングを作成します。検証後は、暗号化キーを再生成しないでください。
{% endhint %}

{% hint style="success" %}
暗号化キー ファイルの形式例:

```
ファイル名: <command-org-name>_org_secret.txt

形式:
<表示名 / 変数名>

<暗号化キー>
```

{% endhint %}

***

## 暗号化キーを IDプロバイダ に追加する

ECE は Okta、Microsoft Entra ID (Azure AD)、および Google Workspace でサポートされています。

<details>

<summary>Okta</summary>

1. Okta の管理者アカウントにログインします。
2. 左側で、 **ディレクトリ > プロファイル エディタ**.
3. 開く **Verkada SSO OIDC User**.
4. 選択 **属性を追加**:
   1. org\_secret.txt ファイルから表示名と変数名（どちらの値も同じ）を追加します。これは "vkdae2ee…" で始まります。
   2. クリック **Save**
5. 選択 **マッピング**:
   1. クリック **Okta User to Verkada SSO OIDC**
   2. 暗号化キーの値（.txt ファイルの 2 つ目の値。引用符を含む）をコピーします
   3. \[マッピング] ページの下部で、新しい変数のテキストボックスに貼り付けます
   4. 中央のアイコンをクリックして、次を選択します **ユーザー作成時と更新時にマッピングを適用**
   5. クリック **マッピングを保存**、次に **今すぐ更新を適用**

{% hint style="danger" %}
マッピング手順を正しく完了することは、ECE カメラの登録プロセスをシームレスに進めるうえで重要です。
{% endhint %}

{% hint style="info" %}
参照してください [カスタム プロファイル属性を追加](https://support.okta.com/help/s/article/How-To-Add-Custom-Profile-Attributes-As-Claims-In-a-ID-Token-or-userinfo?language=en_US) 問題が発生した場合。
{% endhint %}

</details>

<details>

<summary>Microsoft Entra ID (Azure AD)</summary>

1. Azure ポータルにログインします。
2. 検索して選択します **アプリの登録**.
3. 選択 **Verkada SSO OIDC** （表示されない場合は、\[すべてのアプリケーション] を確認してください）。
4. 左側で、 **管理 > アプリ ロール**:
   1. クリック **アプリ ロールを作成**
   2. 追加 **表示名** と **説明** を使用して、 `org_secret.txt` ファイル
   3. \[次の項目] の下で **許可されたメンバーの種類**、選択してください **ユーザー/グループ**
   4. **\[値] には、次の形式で暗号化キーを入力します** `first_value:second_value` （引用符なし）
   5. クリック **適用**
5. 左側で、 **管理 > トークン構成**:
   1. クリック **グループ クレームを追加**
   2. 選択 **セキュリティ グループ** をグループの種類として
   3. 選択 **グループをロール クレームとして発行** を ID として
   4. クリック **追加**
6. 左側で、 **管理 > 認証 > 設定**:
   1. \[次の項目] の下で **暗黙的許可とハイブリッド フロー**、両方を選択 **ID トークン** と **アクセストークン**
   2. クリック **Save**
7. 左側で、 **管理 > マニフェスト**:
   1. 確認 `idToken.additionalProperties.emit_as_roles` が存在する
8. 新しいロールにユーザーを割り当てます:
   1. 検索して選択します **Microsoft Entra ID**
   2. 左側で、 **管理 > エンタープライズ アプリケーション**
   3. クリック **Verkada SSO OIDC**
   4. 左側で、 **管理 > ユーザーとグループ**
   5. クリック **ユーザー/グループを追加**
   6. 作成した新しいロールをユーザーに割り当てる
   7. クリック **割り当て**

</details>

<details>

<summary>Google Workspace</summary>

1. Google 管理コンソールを開きます。
2. 次へ移動します: **ディレクトリ > ユーザー**.
3. 選択 **その他のオプション > カスタム属性を管理**.
4. クリック **カスタム属性を追加** を以下で:
   1. カテゴリ: **ECEInfo**
   2. カスタム フィールド: 名前: **keys**、情報タイプ: **テキスト**、表示設定: **ユーザーと管理者に表示**、値の数: **複数値**
   3. クリック **追加**
5. Verkada オーガナイゼーション' へのアクセスが必要な各ユーザーについて:
   1. 移動 **ディレクトリ > ユーザー** を選択してユーザーを選びます
   2. 展開 **ユーザー情報 > ECEInfo**
   3. クリック **編集**
   4. 表示名と暗号化キーをコロンで区切って追加します: `<表示名>:<暗号化キー>`
   5. クリック **Save**
   6. すべてのユーザーに対して繰り返します

**自動化する場合は**、Google グループを作成し、次にある Apps Script を使用します [Verkada ECE ドキュメント](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf).

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.verkada.com/command/ja/sekyuriti/enterprise-controlled-encryption/enable-enterprise-controlled-encryption.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
