Mods
AWS

IAM Role: AWS/KMS/Admin

PermissionGrant
kms:CancelKeyDeletionAdmin
kms:ConnectCustomKeyStoreAdmin
kms:CreateAliasAdmin
kms:CreateCustomKeyStoreAdmin
kms:CreateGrantAdmin
kms:CreateKeyAdmin
kms:DeleteAliasAdmin
kms:DeleteCustomKeyStoreAdmin
kms:DeleteImportedKeyMaterialAdmin
kms:DisableKeyAdmin
kms:DisableKeyRotationAdmin
kms:DisconnectCustomKeyStoreAdmin
kms:EnableKeyAdmin
kms:EnableKeyRotationAdmin
kms:ImportKeyMaterialAdmin
kms:PutKeyPolicyAdmin
kms:RetireGrantAdmin
kms:RevokeGrantAdmin
kms:ScheduleKeyDeletionAdmin
kms:UpdateAliasAdmin
kms:UpdateCustomKeyStoreAdmin
kms:UpdateKeyDescriptionAdmin
kms:UpdatePrimaryRegionAdmin
kms:DecryptOperator
kms:EncryptOperator
kms:GenerateDataKeyOperator
kms:GenerateDataKeyPairOperator
kms:GenerateDataKeyPairWithoutPlaintextOperator
kms:GenerateDataKeyWithoutPlaintextOperator
kms:GenerateRandomOperator
kms:ReEncryptOperator
kms:ReEncryptFromOperator
kms:ReEncryptToOperator
kms:ReplicateKeyOperator
kms:SignOperator
kms:SynchronizeMultiRegionKeyOperator
kms:TagResourceOperator
kms:UntagResourceOperator
kms:VerifyOperator
kms:DescribeCustomKeyStoresMetadata
kms:DescribeKeyMetadata
kms:GetKeyPolicyMetadata
kms:GetKeyRotationStatusMetadata
kms:GetParametersForImportMetadata
kms:GetPublicKeyMetadata
kms:ListAliasesMetadata
kms:ListGrantsMetadata
kms:ListKeyPoliciesMetadata
kms:ListKeysMetadata
kms:ListResourceTagsMetadata
kms:ListRetirableGrantsMetadata