Updated on 2025-12-02 GMT+08:00

Disabling a Key

Scenario

This section describes how to use the management console to disable one or multiple custom keys, thereby protecting data in urgent cases.

After being disabled, a custom key cannot be used to encrypt or decrypt any data. Before using a disabled key to encrypt or decrypt data, you must enable it by following instructions in Enabling a Key.

Default keys created by KMS cannot be disabled.

Prerequisites

The key you want to disable is in Enabled status.

Procedure

  1. Log in to the management console.
  2. Click in the upper left corner of the management console and select a region or project.
  3. Choose Security > Data Encryption Workshop. The key management page is displayed.
  4. In the row containing the desired key, click Disable.

    Figure 1 Disabling a single key

  5. In the dialog box that is displayed, select I understand the impact of disabling keys and click .

    To disable multiple keys at a time, select them and click Disable in the upper left corner of the list.