> For the complete documentation index, see [llms.txt](https://help.verkada.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://help.verkada.com/command/ko/security/enterprise-controlled-encryption/enable-enterprise-controlled-encryption.md).

# 엔터프라이즈 제어 암호화 사용

{% hint style="info" %}
참조하세요 [엔터프라이즈 제어 암호화(ECE) 개요](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf) 를 참조하세요.
{% endhint %}

***

## 사전 요구 사항

### OIDC 단일 로그인 구성

Verkada는 현재 OIDC를 통한 단일 로그인의 ID 공급자로 Okta, Microsoft Entra ID(Azure AD), Google Workspace만 지원합니다. 설정 가이드는 다음을 참조하세요:

* [Okta](/command/ko/security/identity-providers/okta.md)
* [Microsoft Entra ID](/command/ko/security/identity-providers/microsoft-entra-id.md)
* [Google Workspace](/command/ko/security/identity-providers/google-workspace.md)

{% hint style="danger" %}
ECE를 사용하려면 조직에서 OIDC SSO를 활성화해야 합니다.
{% endhint %}

### Command 모바일 앱 업데이트

조직의 모든 사용자에게 Verkada Command 모바일 앱을 업데이트하도록 요청하세요. 자동 업데이트가 비활성화되지 않은 경우 앱은 자동으로 업데이트됩니다.

* iOS: [Verkada Command](https://apps.apple.com/us/app/verkada-command/id1157022527)
* Android: [Verkada Command](https://play.google.com/store/apps/details?id=com.verkada.android\&hl=en\&gl=US)

업데이트할 **필요가** 없습니다. Verkada Pass 앱을 업데이트할 필요는 없습니다.

***

## ECE 활성화

{% stepper %}
{% step %}
**Verkada Command에서 All Products > Admin으로 이동합니다.**
{% endstep %}

{% step %}
**왼쪽 탐색 메뉴에서 로그인 및 액세스 > 엔터프라이즈 제어 암호화를 선택합니다.**
{% endstep %}

{% step %}
**시작하기를 클릭합니다.**
{% endstep %}

{% step %}
**다음에서 키 생성:**

a. 다음을 클릭합니다 **키 생성**\
b. 암호화 키를 다운로드합니다\
c. [암호화 키를 ID 공급자에 추가](#add-encryption-key-to-identity-provider)\
d. 클릭 **계속**
{% endstep %}

{% step %}
**다음에서 확인:**

a. 다음을 클릭합니다 **로그아웃 및 테스트**\
b. 성공하면 이 페이지로 리디렉션됩니다\
c. 클릭 **계속**
{% endstep %}

{% step %}
**다음에서 기기 등록:**

a. 다음을 클릭합니다 **기기 선택** 을 클릭하고 ECE에 등록할 기기를 선택합니다\
b. 클릭 **기기 등록**

{% hint style="info" %}
다음을 선택하는 것을 권장합니다 **모든 기기 선택** 을 통해 전체 장비에 대한 추가 보안 및 데이터 보호를 보장합니다.
{% endhint %}
{% endstep %}
{% endstepper %}

{% hint style="danger" %}
암호화 키는 한 번만 생성해야 합니다. 이 키를 사용하여 OIDC 공급자에서 매핑을 만드세요. 확인 후에는 암호화 키를 다시 생성하지 마세요.
{% endhint %}

{% hint style="success" %}
암호화 키 파일 형식 예시:

```
파일 이름: <command-org-name>_org_secret.txt

형식:
<표시 이름 / 변수 이름>

<암호화 키>
```

{% endhint %}

***

## 암호화 키를 ID 공급자에 추가

ECE는 Okta, Microsoft Entra ID(Azure AD), Google Workspace에서 지원됩니다.

<details>

<summary>Okta</summary>

1. Okta 관리자 계정에 로그인합니다.
2. 왼쪽에서 **디렉터리 > 프로필 편집기**.
3. 열기 **Verkada SSO OIDC 사용자**.
4. 선택 **Add Attribute**:
   1. org\_secret.txt 파일에서 표시 이름과 변수 이름(두 값은 동일함)을 추가합니다. "vkdae2ee…"로 시작합니다.
   2. 클릭 **저장**
5. 선택 **매핑**:
   1. 클릭 **Okta 사용자에서 Verkada SSO OIDC로**
   2. 암호화 키 값(.txt 파일의 두 번째 값, 따옴표 포함)을 복사합니다.
   3. 매핑 페이지 하단에서 새 변수의 텍스트 상자에 붙여넣습니다.
   4. 가운데 아이콘을 클릭하고 다음을 선택합니다 **사용자 생성 및 업데이트 시 매핑 적용**
   5. 클릭 **Save Mappings**, 그런 다음 **Apply updates now**

{% hint style="danger" %}
원활한 ECE 카메라 등록 프로세스를 위해서는 매핑 단계를 올바르게 완료하는 것이 중요합니다.
{% endhint %}

{% hint style="info" %}
참조하세요 [사용자 지정 프로필 속성 추가](https://support.okta.com/help/s/article/How-To-Add-Custom-Profile-Attributes-As-Claims-In-a-ID-Token-or-userinfo?language=en_US) 문제가 발생하는 경우.
{% endhint %}

</details>

<details>

<summary>Microsoft Entra ID(Azure AD)</summary>

1. Azure 포털에 로그인합니다.
2. 검색하여 선택합니다 **앱 등록**.
3. 선택 **Verkada SSO OIDC** (보이지 않으면 모든 애플리케이션 확인).
4. 왼쪽에서 **관리 > 앱 역할**:
   1. 클릭 **앱 역할 만들기**
   2. 다음을 추가합니다 **표시 이름** 및 **설명** 에서 동일한 첫 번째 값을 사용하여 `org_secret.txt` 파일
   3. 아래 **허용된 멤버 유형**를 선택하고 **사용자/그룹**
   4. **값 아래에 다음 형식으로 암호화 키를 입력합니다** `first_value:second_value` (따옴표 제외)
   5. 클릭 **적용**
5. 왼쪽에서 **관리 > 토큰 구성**:
   1. 클릭 **그룹 클레임 추가**
   2. 선택 **보안 그룹** 를 그룹 유형으로
   3. 선택 **그룹을 역할 클레임으로 발급** 를 ID로
   4. 클릭 **Add**
6. 왼쪽에서 **관리 > 인증 > 설정**:
   1. 아래 **암시적 허용 및 하이브리드 흐름**, 둘 다 선택합니다 **ID 토큰** 및 **액세스 토큰**
   2. 클릭 **저장**
7. 왼쪽에서 **관리 > 매니페스트**:
   1. 확인 `idToken.additionalProperties.emit_as_roles` 가 존재합니다
8. 새 역할에 사용자를 할당합니다:
   1. 검색하여 선택합니다 **Microsoft Entra ID**
   2. 왼쪽에서 **관리 > 엔터프라이즈 애플리케이션**
   3. 클릭 **Verkada SSO OIDC**
   4. 왼쪽에서 **관리 > 사용자 및 그룹**
   5. 클릭 **사용자/그룹 추가**
   6. 사용자를 새로 만든 역할에 할당
   7. 클릭 **할당**

</details>

<details>

<summary>Google Workspace</summary>

1. Google 관리 콘솔에 로그인합니다.
2. 다음으로 이동하세요 **디렉터리 > 사용자**.
3. 선택 **추가 옵션 > 사용자 지정 속성 관리**.
4. 클릭 **사용자 지정 속성 추가** 다음과 같이:
   1. 범주: **ECEInfo**
   2. 사용자 지정 필드: 이름: **키**, 정보 유형: **텍스트**, 표시 여부: **사용자 및 관리자에게 표시**, 값 수: **다중 값**
   3. 클릭 **Add**
5. Verkada 조직에 대한 액세스가 필요한 각 사용자에 대해:
   1. 다음으로 이동합니다. **디렉터리 > 사용자** 을 선택하고 사용자를 선택합니다
   2. 확장 **사용자 정보 > ECEInfo**
   3. 클릭 **편집**
   4. 표시 이름과 암호화 키를 콜론으로 구분하여 추가합니다: `<표시 이름>:<암호화 키>`
   5. 클릭 **저장**
   6. 모든 사용자에 대해 반복합니다

**자동화를 위해**Google 그룹을 만들고 다음의 앱 스크립트를 사용합니다 [Verkada ECE 문서](https://docs.verkada.com/docs/enterprise-controlled-encryption-overview.pdf).

</details>


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://help.verkada.com/command/ko/security/enterprise-controlled-encryption/enable-enterprise-controlled-encryption.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
