For the KMS key to be used, the following operations must be permitted for the user accessing AWS KMS.
Encrypt
Decrypt
DescribeKey