aws AWS What's New ·

Amazon QuickSight supports customer-managed encryption keys

securityawsgaarchitect
feature patch

Amazon QuickSight now allows customers to encrypt their data using their own AWS Key Management Service (KMS) keys. This provides enhanced security control and audit capabilities for organizations with strict compliance needs, enabling them to manage encryption for their business intelligence data. The feature is generally available and requires keys to be in the same AWS account and region as QuickSight resources, supporting only symmetric KMS keys.

  • Enable encryption with customer-managed keys
  • Enhanced security control and auditing
  • Flexible management for sensitive data
  • Prerequisites and availability
Features (1)
  • Enable encryption with customer-managed keys

    Amazon QuickSight now supports encrypting data using customer-managed keys (CMK) through AWS Key Management Service (KMS). This allows organizations to manage their own encryption keys for enhanced security and compliance.

Enhancements (1)
  • Enhanced security control and auditing

    Using customer-managed keys provides greater security control and audit capabilities via AWS CloudTrail integration. Users can trace all data access for security auditing and revoke access to compromised keys quickly.

Notes (2)
  • Flexible management for sensitive data

    The feature supports multiple CMKs with one default key per AWS account per region, offering flexibility to manage encryption across different datasets. It maintains granular control over sensitive business intelligence data.

  • Prerequisites and availability

    Customer-managed keys must be created in the same AWS account and region as QuickSight resources, and only symmetric AWS KMS keys are supported. This feature is generally available in all AWS Regions where Amazon QuickSight is available.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/06/amazon-quick-research-cm-keys

Related releases