Amazon Cognito now supports customer managed key for encryption at rest
News
Amazon Cognito now supports customer managed keys in AWS KMS for encrypting user pool data at rest, providing organizations with full control over encryption keys.
- Define organizational policies and revoke access by disabling or deleting keys
- Create and manage customer managed key lifecycle and usage permissions in AWS KMS
- Configure customer managed keys when creating new user pools or update existing ones
- Monitor and audit key usage with AWS CloudTrail for visibility into identity data access
- Available in Essentials and Plus tiers at no additional cost; standard AWS KMS charges apply
Customer managed keys enable organizations to achieve data governance objectives while maintaining full control over encryption and access to user pool data.
The AWS News Feed is currently looking for gold sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.
Related articles
Jul 20
2026
2026
Amazon CloudWatch Synthetics now supports customer managed encryption keys
Jul 22
2026
2026
AWS Lambda durable functions now supports customer managed key encryption
Jul 6
2026
2026
Amazon Cognito now supports self-service provisioned API rate limits
Jul 15
2026
2026
Amazon Cognito now supports importing users with password hashes
The AWS News Feed is currently looking for silver sponsors. If you want to support the AWS community and reach a large audience of AWS professionals, consider sponsoring the AWS News Feed.