Amazon Macie is an AWS service that inventories Amazon S3 general purpose buckets, flags bucket security and access-control issues, and discovers sensitive data inside S3 objects. Its documented scope stops there: it is not a general scanner for databases, file servers, or other data stores. Two details matter most for security teams. A Macie result set with no findings does not prove that every object was analyzed, and Macie keeps its own object-level discovery results for only 90 days unless you export them.
What Macie monitors
Macie works on two kinds of material in an AWS account. The first is the bucket inventory: Macie evaluates S3 general purpose buckets for security and access-control problems, and it can generate policy findings when a configuration change creates a potential security or privacy concern. The second is the object content: Macie analyzes objects to find sensitive data, using machine learning and pattern matching for detection.
Enablement is Region-specific. You enable Macie for each Region where you want it to work, and it covers the S3 general purpose buckets in that Region. A second Region needs its own enablement and its own settings.
Two discovery approaches
Macie offers two ways to find sensitive data. They answer different questions, and they are priced differently, so it helps to understand both before you turn anything on.
The Tool Desk
Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →#1 Best Overall
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
- There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
- Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
- Reorder SKU: LOG-100-M3CW-PP(Security-Report)
Automated sensitive data discovery
Automated discovery runs continuously. It evaluates the bucket inventory and uses sampling techniques to select representative objects for analysis. This gives you broad, ongoing visibility across the buckets in a Region without you choosing individual objects. Administrators can adjust its scope, including excluding specific buckets, and organization administrators have account-level controls. AWS states that results typically become reviewable within 48 hours of enablement, depending on account settings and how far analysis has progressed. Treat that as a typical expectation, not a completion deadline.
Because the method is sample-based, automated discovery should be described as broad visibility. It is not an object-by-object guarantee.
Rank #2
- Made in USA - Proudly produced in Ohio by a Veteran-owned business
- Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
- Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
- Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
- Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)
Sensitive data discovery jobs
A discovery job is a defined, user-controlled analysis. You choose the buckets directly or select buckets that meet criteria you define, and you decide whether the job runs once or on a schedule. You can refine what the job looks for with managed data identifiers, custom data identifiers, and allow lists. The job workflow shows an estimated cost before you submit it. The final charge depends on how much data is analyzed and on other applicable AWS charges.
Jobs suit a defined investigation, a compliance review of specific buckets, or a recurring scan of a known set of buckets. They still depend on supported objects and on the detection criteria you configure.
Recommended Free Tools
How the two compare
| Factor | Automated sensitive data discovery | Sensitive data discovery job |
|---|---|---|
| Coverage strategy | Representative sampling across the bucket inventory | Analysis of the buckets and criteria you select |
| Control | Service-selected objects that run continuously; you set scope and exclusions | You set buckets, identifiers, allow lists, and whether the job runs once or on a schedule |
| Cost planning | Ongoing charges across buckets evaluated, objects monitored, and data analyzed | Charges for the data the job analyzes, plus any related S3 request charges |
| Free trial | Included within the trial, subject to the stated terms and cap | Not included in the trial |
| Best fit | Broad, continuous visibility | Defined reviews and recurring targeted scans |
The two are complementary rather than substitutes. Many teams use automated discovery to see where sensitive data may sit and jobs to examine specific buckets more closely.
Findings and discovery results are different records
Macie produces two separate outputs, and an audit trail needs both to be understood correctly.
Rank #4
| Record | What it shows | Retention in Macie |
|---|---|---|
| Policy findings | Potential security or privacy issues with an S3 bucket’s configuration | 90 days |
| Sensitive data findings | Sensitive data detected in a specific object: category or type, occurrence count, affected bucket and object, and detection time. The sensitive data itself is not included. | 90 days |
| Sensitive data discovery results | Object-level analysis records, including objects with detections, objects with no detections, and objects Macie could not analyze | 90 days in Macie; longer retention requires an S3 repository |
Findings can be filtered, grouped, sorted, and managed with suppression rules. Suppression changes what you see in the findings list; it does not change what Macie analyzed. Discovery results are the record that tells you what was examined, which is why they matter for investigations.
Setting up Macie
AWS’s getting-started process follows a short sequence. The order below reflects that process.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallOutdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchBest Value
- Confirm that the IAM identity you use has the permissions required to enable Macie. Macie needs permission to create its service-linked role.
- Select the AWS Region where you want Macie to work. Each Region is enabled separately.
- Enable Macie in that Region. Macie can begin building the S3 bucket inventory within minutes.
- Review the permissions of the service-linked role, if your governance process requires it.
- Decide whether you need to keep discovery results beyond 90 days. If you do, configure an S3 repository for them. AWS recommends doing this within 30 days of enabling the service, because Macie’s own retention for those results is limited to 90 days.
The repository is configured per Region, and it requires an S3 bucket and a KMS key for encryption. Plan the bucket and key before you enable the repository, and make sure the account that owns them can read and write the results.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What “no findings” does and does not mean
A clean result set is only as complete as the analysis behind it. Macie analyzes only objects it can access and that fall within its supported storage classes and file or storage formats. AWS’s supported-format list includes common document types such as PDF, Microsoft Excel, and Word, along with other supported types. Check that list against the formats in your own buckets rather than assuming full coverage.
Several conditions can leave objects unanalyzed:
- The object is in an S3 storage class Macie does not support.
- The file or storage format is not on the supported list.
- Macie lacks permission to read the object, or the object has another issue that prevents analysis.
- The object falls outside the scope of automated discovery’s sample, or outside a job’s bucket selection.
This is why discovery results list unanalyzed objects separately. Review that list before concluding that a bucket is clean.
What drives cost
AWS prices Macie on three usage dimensions:
- Buckets evaluated for inventory and security monitoring.
- Objects monitored for automated sensitive data discovery.
- Data analyzed for sensitive data discovery, whether through automated discovery or through jobs.
Related AWS usage can add to the bill. S3 requests, and customer-managed KMS key use where your configuration relies on it, are charged separately from Macie.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Repair Windows errors before they cause bigger problemsFix Now →| Item | Stated terms in AWS’s Macie pricing material (checked 7 October 2026) |
|---|---|
| Free trial | 30 days from first enablement in a Region. Automated discovery is included within the trial, subject to the stated terms and cap. Targeted discovery jobs are not included. |
| Trial analysis amount | The pricing page states 150 GB per account of data inspected for automated discovery within the 30-day trial. |
| Monthly free tier | 1 GB per month of analyzed S3 object data for discovery, subject to account and consolidated-billing terms. |
| Published example | $151.50 per month, US East (Northern Virginia), with 15 buckets, 10 million supported objects, and 150 GB analyzed for automated discovery. This is an illustration under those assumptions, not a quote or a general rate. |
| Per-unit rates | Not stated in the material reviewed; check the regional rates on the AWS pricing page for your Region. |
Because the example is dated and Region-specific, build your own estimate with the bucket count, the number of supported objects, and the volume you expect to analyze. Run the job estimate before submitting any job so the figure reflects your actual data.
Quick Recap
Choosing an approach
Use this framework to decide where to start:
- You need continuous visibility across many buckets and accept sampling: start with automated discovery and review its scope and exclusions.
- You have a specific set of buckets to examine or a compliance question with a defined boundary: run a discovery job with explicit bucket selection, identifiers, and, if needed, a schedule.
- You must keep an object-level record for longer than 90 days: configure an S3 repository for discovery results before the first analysis you need to keep.
- Your data lives outside S3 general purpose buckets: Macie does not cover it, so plan a separate control for that store.
Common pitfalls
- Assuming a bucket is clean because findings are empty, without checking the unanalyzed objects in discovery results.
- Letting discovery results age out of Macie’s 90-day window with no repository configured.
- Treating sampled automated results as a full inventory of sensitive data.
- Estimating cost from the example price instead of your own bucket, object, and data volumes.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




