Select your cookie preferences

We use essential cookies and similar tools that are necessary to provide our site and services. We use performance cookies to collect anonymous statistics, so we can understand how customers use our site and make improvements. Essential cookies cannot be deactivated, but you can choose “Customize” or “Decline” to decline performance cookies.

If you agree, AWS and approved third parties will also use cookies to provide useful site features, remember your preferences, and display relevant content, including relevant advertising. To accept or decline all non-essential cookies, choose “Accept” or “Decline.” To make more detailed choices, choose “Customize.”

Using an AWS KMS customer managed key for encryption in member account

Focus mode
Using an AWS KMS customer managed key for encryption in member account - Application Migration Service

If you decide to use a customer managed key, or if your default Amazon EBS encryption key is a customer managed key in member account, you must add permissions to the AWSApplicationMigrationSharingRole_<MANAGEMENT_ACCOUNT_ID> to allow management account to use it.

Using Administrator access, add these permissions to the AWSApplicationMigrationSharingRole_<MANAGEMENT_ACCOUNT_ID>:

{ "Version": "2012-10-17", "Statement": [ { "Sid": "Allow management account use CMK of member account", "Effect": "Allow", "Action": [ "kms:CreateGrant", "kms:DescribeKey", "kms:ReEncrypt*", "kms:GenerateDataKey*" ], "Resource": "$KEY_ARN" }] }
PrivacySite termsCookie preferences
© 2025, Amazon Web Services, Inc. or its affiliates. All rights reserved.