Skip to main content

Amazon IAM Identity Center organization instances now support customer-managed KMS keys for encryption at rest

Posted on: Sep 23, 2025

IAM Identity Center now supports customer-managed Amazon Key Management Service (KMS) keys for encrypting workforce identity data, including user and group attributes. While Amazon-owned keys are used by default, customer-managed keys (CMKs) provide granular control over identity data access, enhancing security and compliance capabilities. IAM Identity Center helps you securely create, or connect, your workforce identities and manage their access centrally across Amazon Web Services applications and accounts.

You create a CMK and manage its lifecycle and usage permissions in Amazon KMS. You can configure the CMK in your IAM Identity Center instance either while enabling a new organization instance or on an existing one. You can then use Amazon CloudTrail to monitor and audit the usage of your CMK for access to identity data in IAM Identity Center.

Support for CMKs in organization instances of IAM Identity Center is now available for access to accounts and select Amazon Web Services applications in all Amazon Web Services regions, including the Amazon Web Services China (Beijing) Region, operated by Sinnet and the Amazon Web Services China (Ningxia) Region, operated by NWCD. Standard Amazon KMS charges apply to storing and using CMKs. IAM Identity Center is provided at no additional cost.

To learn more about IAM Identity Center, visit the product detail page. To get started with using CMKs in IAM Identity Center please refer to the User Guide.