Add an aws-managed policy for kms:Decrypt and kms:GenerateDataKey to attach to aws-quicksight-service-role-v0

Would like the aws-quicksight-role-v0 to natively support IAM policy permissions for kms:Decrypt and kms:GenerateDataKey to avoid having to create and attach a custom policy with that permission for querying datasets from kms-encrypted s3 buckets. Is there an open PFR for this?

Hi @Nelly,

At AWS, our roadmap is primarily driven by our customers. Your feedback helps us build a better service. I have tagged this as a feature request.

About checking for a PFR, please contact your account manager for them to check this internally.

Kind regards,
Andres.