By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
World of SoftwareWorld of SoftwareWorld of Software
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Search
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
Reading: Bring Your Own Key (BYOK): AWS IAM Identity Center Adopts CMKs to Meet Enterprise Compliance Needs
Share
Sign In
Notification Show More
Font ResizerAa
World of SoftwareWorld of Software
Font ResizerAa
  • Software
  • Mobile
  • Computing
  • Gadget
  • Gaming
  • Videos
Search
  • News
  • Software
  • Mobile
  • Computing
  • Gaming
  • Videos
  • More
    • Gadget
    • Web Stories
    • Trending
    • Press Release
Have an existing account? Sign In
Follow US
  • Privacy
  • Terms
  • Advertise
  • Contact
Copyright © All Rights Reserved. World of Software.
World of Software > News > Bring Your Own Key (BYOK): AWS IAM Identity Center Adopts CMKs to Meet Enterprise Compliance Needs
News

Bring Your Own Key (BYOK): AWS IAM Identity Center Adopts CMKs to Meet Enterprise Compliance Needs

News Room
Last updated: 2025/10/19 at 6:15 AM
News Room Published 19 October 2025
Share
Bring Your Own Key (BYOK): AWS IAM Identity Center Adopts CMKs to Meet Enterprise Compliance Needs
SHARE

AWS recently announced that its IAM Identity Center service supports customer-managed KMS keys (CMKs) for encryption at rest. Organizations can use their own keys to encrypt Identity Center identity data at rest.

IAM Identity Center is a cloud service that centralizes the management of single sign-on (SSO) access to multiple AWS accounts and cloud applications. While Identity Center data has always been encrypted at rest using AWS-owned KMS keys, the new CMK support allows organizations to bring their own keys to encrypt their workforce identity data, such as user and group attributes.

The integration with AWS Key Management Service (KMS) is crucial as it transfers the control of the encryption key’s lifecycle (creation, rotation, and deletion) directly to the customer.

(Source: AWS News blog)

Alex Milanovic, a senior product manager, AWS IAM Identity Center, summarized the core benefits in a LinkedIn post:

  • Complete control over their encryption keys.
  • Granular access management for identity data via KMS and IAM policies, ensuring only authorized principals can access their encrypted data.
  • Enhanced audit capabilities through detailed AWS CloudTrail logs of key usage.
  • Strengthened compliance posture for regulated industries requiring data sovereignty.

Sébastien Stormacq, developer evangelist at AWS, further detailed the level of control this enables:

You can configure granular access controls to keys with AWS Key Management Service (AWS KMS) key policies and IAM policies, helping to ensure that only authorized principals can access your encrypted data.

For auditing and regulatory purposes, the entire process is logged via AWS CloudTrail, providing a detailed record of key usage. This level of granular control over encryption keys is often a prerequisite for enterprises operating in highly regulated industries.

The ability to use CMKs for data at rest is a standard requirement for enterprises due to compliance or security strategy, such as Bring Your Own Key. Other hyperscalers and products widely support it through their respective key management services.

Microsoft Azure facilitates this through Azure Key Vault, enabling customers to encrypt sensitive data across various services and authenticate access via Microsoft Entra ID. Similarly, Google Cloud offers CMKs via Cloud Key Management Service (Cloud KMS), providing a cryptographic boundary and full key lifecycle control for data in services like Cloud Storage and BigQuery.

Identity Center supports both single-region and multi-region keys to meet users’ deployment needs. However, currently, Identity Center instances can only be deployed in a single region. Yet, the company recommends using multi-region AWS KMS keys unless company policies restrict users to single-region keys. It states that multi-region keys provide consistent key material across regions while maintaining independent key infrastructure in each region.

Lastly, the capability is currently available in all AWS commercial regions, AWS GovCloud (US), and AWS China regions. Furthermore, pricing-wise, users pay for Identity IAM Center, and for Standard AWS KMS charges apply for key storage and API usage.

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
Share This Article
Facebook Twitter Email Print
Share
What do you think?
Love0
Sad0
Happy0
Sleepy0
Angry0
Dead0
Wink0
Previous Article The Zipper Is Getting Its First Major Upgrade in 100 Years The Zipper Is Getting Its First Major Upgrade in 100 Years
Next Article These 6 lesser-known free apps make my life easier These 6 lesser-known free apps make my life easier
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Stay Connected

248.1k Like
69.1k Follow
134k Pin
54.3k Follow

Latest News

Free two-hour delivery from Apple Stores now available for a limited time
Free two-hour delivery from Apple Stores now available for a limited time
News
Is State Street SPDR S&P Software & Services ETF (XSW) a strong ETF right now?
Is State Street SPDR S&P Software & Services ETF (XSW) a strong ETF right now?
News
Exploring Ytmp3: A Popular YouTube to MP3 Converter
Exploring Ytmp3: A Popular YouTube to MP3 Converter
Gadget
Best Apple Watch apps for boosting your productivity |  News
Best Apple Watch apps for boosting your productivity | News
News

You Might also Like

Free two-hour delivery from Apple Stores now available for a limited time
News

Free two-hour delivery from Apple Stores now available for a limited time

1 Min Read
Is State Street SPDR S&P Software & Services ETF (XSW) a strong ETF right now?
News

Is State Street SPDR S&P Software & Services ETF (XSW) a strong ETF right now?

5 Min Read
Best Apple Watch apps for boosting your productivity |  News
News

Best Apple Watch apps for boosting your productivity | News

10 Min Read
The Bear Elite Hybrid is the coolest mattress I’ve ever tested — and now it’s at its lowest price of the year
News

The Bear Elite Hybrid is the coolest mattress I’ve ever tested — and now it’s at its lowest price of the year

3 Min Read
//

World of Software is your one-stop website for the latest tech news and updates, follow us now to get the news that matters to you.

Quick Link

  • Privacy Policy
  • Terms of use
  • Advertise
  • Contact

Topics

  • Computing
  • Software
  • Press Release
  • Trending

Sign Up for Our Newsletter

Subscribe to our newsletter to get our newest articles instantly!

World of SoftwareWorld of Software
Follow US
Copyright © All Rights Reserved. World of Software.
Welcome Back!

Sign in to your account

Lost your password?