Home icon

AWS KMS now tracks last usage of all KMS keys

News



This article announces that AWS KMS now tracks the last cryptographic operation performed on all KMS keys, providing visibility without manual log analysis.

  • View timestamp, operation type, and CloudTrail event ID for last key usage
  • Accessible via AWS KMS console or API
  • Helps identify unused keys for cleanup and verify active key usage
  • New condition key (kms:TrailingDaysWithoutKeyUsage) protects against accidental deletion
  • Available in all AWS Regions including GovCloud and China Regions

This feature simplifies key management and compliance tracking by providing built-in visibility into KMS key usage patterns.



Go to article

The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.

Related articles

Jun 2
2026
Identify unused AWS KMS keys and prevent accidental key deletions
Mar 17
2025
AWS KMS CloudWatch metrics help you better track and understand how your KMS keys are being used
Dec 16
2024
AWS KMS: How many keys do I need?
Jun 6
2025
AWS KMS launches on-demand key rotation for imported keys

The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.