User-Specific Secrets on AWS: KMS and MFA with Developer Credentials

ACM.84 Granting an IAM Group permission to use a KMS key in a Key Policy

Teri Radichel
Cloud Security
Published in
14 min readOct 18, 2022


Part of my series on Automating Cybersecurity Metrics. Metrics, MFA, Passwords and Encryption. The Code.

Free Content on Jobs in Cybersecurity | Sign up for the Email List

We’ve been working on adding a user-specific secret in Secrets Manager in the past few posts and considered how to deploy secrets in a manner that supports non-repudiation.



Teri Radichel
Cloud Security

CEO 2nd Sight Lab | Penetration Testing & Assessments | AWS Hero | Masters of Infosec & Software Engineering | GSE 240 etc | IANS | SANS Difference Makers Award