AWS-Managed, Customer-Managed, and AWS-Owned Keys
~8 min read
Three tiers of KMS key control, trading setup effort and cost for granularity.
AWS-Managed, Customer-Managed, and AWS-Owned Keys is a Pro topic
Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.
Key points
- •AWS-owned: invisible, used internally by services, zero configuration or visibility
- •AWS-managed: visible, automatic default per-service, free, fixed policy and rotation
- •Customer-managed: full control over policy/rotation/deletion, small cost, needed for compliance-grade access control
- •Choose customer-managed whenever you need granular, auditable control beyond a service's default behavior