AWS-Managed, Customer-Managed, and AWS-Owned Keys

~8 min read

Three tiers of KMS key control, trading setup effort and cost for granularity.

AWS-Managed, Customer-Managed, and AWS-Owned Keys is a Pro topic

Sign in, then upgrade to Pro or Power to unlock this topic and the full AWS curriculum.

Key points

  • AWS-owned: invisible, used internally by services, zero configuration or visibility
  • AWS-managed: visible, automatic default per-service, free, fixed policy and rotation
  • Customer-managed: full control over policy/rotation/deletion, small cost, needed for compliance-grade access control
  • Choose customer-managed whenever you need granular, auditable control beyond a service's default behavior