IAM Identity Center now supports customer-managed AWS Key Management Service (KMS) keys for encrypting workforce identity data, including user and group attributes. While AWS-owned keys are used by default, customer-managed keys (CMKs) provide granular control over identity data access, enhancing security and compliance capabilities. IAM Identity Center helps you securely create, or connect, your workforce identities and manage their access centrally across AWS applications and accounts.
You create a CMK and manage its lifecycle and usage permissions in AWS KMS. You can configure the CMK in your IAM Identity Center instance either while enabling a new organization instance or on an existing one. You can then use AWS CloudTrail to monitor and audit the usage of your CMK for access to identity data in IAM Identity Center.
Support for CMKs in organization instances of IAM Identity Center is now available for access to accounts and select AWS applications in all AWS Regions where IAM Identity Center is available. Standard AWS KMS charges apply to storing and using CMKs. IAM Identity Center is provided at no additional cost.
To learn more about IAM Identity Center, visit the product detail page. To get started with using CMKs, please refer to the IAM Identity Center User Guide.
Categories: general:products/aws-iam-identity-center,marketing:marchitecture/security-identity-and-compliance
Source: Amazon Web Services
Latest Posts
- Microsoft Entra passkeys on Windows now support phishing-resistant sign-in [MC1247893]
![Microsoft Entra passkeys on Windows now support phishing-resistant sign-in [MC1247893] 2 pexels yankrukov 8866797](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Outlook: Support for recommended and automatically applied sensitivity labels in Outlook for iOS and Android [MC1247891]
![Outlook: Support for recommended and automatically applied sensitivity labels in Outlook for iOS and Android [MC1247891] 3 pexels inspiredimages 133190](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- (Updated) Microsoft Edge: Microsoft 365 Copilot will support summarization and contextual grounding [MC1187682]
![(Updated) Microsoft Edge: Microsoft 365 Copilot will support summarization and contextual grounding [MC1187682] 4 pexels eye4dtail 216798](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)
- Microsoft Viva Glint: AI-generated survey insights with Copilot highlights [MC1247887]
![Microsoft Viva Glint: AI-generated survey insights with Copilot highlights [MC1247887] 5 pexels anniroenkae 15578416](data:image/svg+xml;base64,PHN2ZyB3aWR0aD0iMSIgaGVpZ2h0PSIxIiB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciPjwvc3ZnPg==)

![Microsoft Entra passkeys on Windows now support phishing-resistant sign-in [MC1247893] 2 pexels yankrukov 8866797](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-yankrukov-8866797-150x150.webp)
![Outlook: Support for recommended and automatically applied sensitivity labels in Outlook for iOS and Android [MC1247891] 3 pexels inspiredimages 133190](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-inspiredimages-133190-150x150.webp)
![(Updated) Microsoft Edge: Microsoft 365 Copilot will support summarization and contextual grounding [MC1187682] 4 pexels eye4dtail 216798](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-eye4dtail-216798-150x150.webp)
![Microsoft Viva Glint: AI-generated survey insights with Copilot highlights [MC1247887] 5 pexels anniroenkae 15578416](https://mwpro.co.uk/wp-content/uploads/2025/06/pexels-anniroenkae-15578416-150x150.webp)
![Updates available for Microsoft 365 Apps for Current Channel [MC1158256] 7 Updates available for Microsoft 365 Apps for Current Channel [MC1158256]](https://mwpro.co.uk/wp-content/uploads/2024/08/pexels-karolina-grabowska-4219862-150x150.webp)