AWS KMS now tracks last usage of all KMS keys
News
This article announces that AWS KMS now tracks the last cryptographic operation performed on all KMS keys, providing visibility without manual log analysis.
- View timestamp, operation type, and CloudTrail event ID for last key usage
- Accessible via AWS KMS console or API
- Helps identify unused keys for cleanup and verify active key usage
- New condition key (kms:TrailingDaysWithoutKeyUsage) protects against accidental deletion
- Available in all AWS Regions including GovCloud and China Regions
This feature simplifies key management and compliance tracking by providing built-in visibility into KMS key usage patterns.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.