This section describes IAM's fine-grained permissions management for your KMS resources. With IAM, you can:
If your account does not need individual IAM users, you may skip over this chapter.
This section describes the procedure for granting permissions (see Figure 1).
Before authorizing permissions to a user group, you need to know which KMS permissions can be added to the user group. Table 1 lists the KMS system policies.
Create a user group on the IAM console and grant the user group the KMS CMKFullAccess permission (indicating full permissions for keys).
Create a user on the IAM console and add the user to the user group created in 1.