Status: IN
The three minimum KMS key policy permissions required for AWS Backup operations are `kms:CreateGrant`, `kms:GenerateDataKey`, and `kms:Decrypt`.
Source: entries/2026/03/12/aws-backup-latest-devguide-encryptionhtml.md
JSON