logo

Identify unused AWS KMS keys and prevent accidental key deletions

ID: 6a9d8d76-868d-5fd8-960a-6805e6c6a01a

STIX ID: report--6a9d8d76-868d-5fd8-960a-6805e6c6a01a

Feed Name: AWS Security Blog

Date Published: 2026-06-02

Date Updated: 2026-06-03

Author: Andrea Rossi

...
...

This AWS KMS documentation announces the GetKeyLastUsage API, which reports the timestamp, operation type, CloudTrail event ID, and KMS request ID for the most recent cryptographic use of a key. It explains the tracking period (tracking began April 23, 2026), how to view last-use data in the console and CLI, provides example use cases and a sample script to find unused keys, offers a policy example (kms:TrailingDaysWithoutKeyUsage) to prevent accidental deletion or disabling of recently used keys, and calls out important considerations such as CloudTrail remaining the authoritative audit source and the irreversible impact of key deletion.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.