AWS managed key is created, managed and used on your behalf by an AWS service. You have permission to view the AWS managed keys in your account and audit their use in AWS CloudTrail logs. However, you cannot change any properties of AWS managed keys, rotate them, change their key policies, or schedule them for deletion.