1 Answer
- Newest
- Most votes
- Most comments
1
If the KMS key policy doesn't permit any still-existing principal access and if it doesn't delegate at least the key policy modification permission to IAM in the account (by granting the permission to the local account's "root" principal), and if there is no KMS key grant that would grant equivalent access to an existing principal, then the only way to restore access is by raising a ticket with AWS support, who can reset the key policy on your behalf.
Relevant content
- asked 8 years ago
- asked 2 years ago
- asked 3 years ago
- AWS OFFICIALUpdated 23 days ago
- AWS OFFICIALUpdated 2 years ago
