AWS Security ChangesHomeSearch

AWS ebs: Document default EBS encryption key and how to change it

Service: ebs · 2026-09-27 · Documentation medium

File: ebs/latest/userguide/encryption-by-default.md · Type: encryption

Summary

Adds a new 'Default encryption key' section explaining that EBS auto-creates an AWS managed KMS key (alias aws/ebs) per Region, and provides console, AWS CLI, and PowerShell steps to change the default encryption key to a customer managed key.

Security assessment

The added content documents EBS default encryption behavior and how to switch to a customer managed KMS key, which is encryption/key-management guidance rather than a fix for a specific vulnerability.

Evidence

+Amazon EBS automatically creates a unique AWS managed key in each Region where you create Amazon EBS resources. The alias for this KMS key is `aws/ebs`. This is your default encryption key. You can change the default encryption key to a customer managed key.

Diff

diff --git a/ebs/latest/userguide/encryption-by-default.md b/ebs/latest/userguide/encryption-by-default.md
index 7f7ac3163..c69878019 100644
--- a//ebs/latest/userguide/encryption-by-default.md
+++ b//ebs/latest/userguide/encryption-by-default.md
@@ -6,0 +7,2 @@
+Default encryption key
+
@@ -183,0 +186,42 @@ You can't change the KMS key that is associated with an existing snapshot or enc
+## Default encryption key
+
+Amazon EBS automatically creates a unique AWS managed key in each Region where you create Amazon EBS resources. The alias for this KMS key is `aws/ebs`. This is your default encryption key. You can change the default encryption key to a customer managed key.
+
+To change the default encryption key for a Region, use one of the following methods.
+
+Console
+    
+
+###### To change the default encryption key for a Region
+
+  1. Open the Amazon EC2 console at [https://console.aws.amazon.com/ec2/](https://console.aws.amazon.com/ec2/).
+
+  2. From the navigation bar, select the Region.
+
+  3. From the navigation pane, select **Settings** , and then select the **Data protection and security** tab.
+
+  4. In the **EBS encryption** section, choose **Manage**.
+
+  5. For **Default encryption key** , select the KMS key ID that you want to use.
+
+  6. Choose **Update EBS encryption**.
+
+
+
+
+AWS CLI
+    
+
+Use the [modify-ebs-default-kms-key-id](https://docs.aws.amazon.com/cli/latest/reference/ec2/modify-ebs-default-kms-key-id.html) command.
+    
+    
+    aws ec2 modify-ebs-default-kms-key-id --kms-key-id key-id --region region
+
+PowerShell
+    
+
+Use the [Edit-EC2EbsDefaultKmsKeyId](https://docs.aws.amazon.com/powershell/latest/reference/items/Edit-EC2EbsDefaultKmsKeyId.html) cmdlet.
+    
+    
+    Edit-EC2EbsDefaultKmsKeyId -KmsKeyId key-id -Region region
+