Automatic Key Rotation enables scheduled creation of new key versions without manual intervention. Based on the configured rotation policy, ESKM automatically generates a new version of the selected key and uploads it to AWS Key Management Service. Older key versions are retained and continue to be available for decrypting previously encrypted data.
Auto Rotation
Automatic Rotation can be configured during key creation or enabled later by editing an existing key. Administrators can modify the rotation settings by enabling/disabling Auto Rotation for the desired key.