Note
Amazon Cognito encrypts customer content internally and doesn't support customer provided keys.
AWS managed policies
Note
Because creating a new identity pool also requires creating IAM roles, any user you want to be able to create new identity pools with must have the admin policy applied as well.