DriversRecommendedOutdated drivers can make a good PC feel brokenScan driver issues before chasing fixes manually.Scan NowOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
World desk6 min

Madhu Meets Macie: Exploring Amazon Macie for Sensitive Data Security

Amazon Macie inventories S3 general purpose buckets, flags bucket security issues, and discovers sensitive data in objects. Here is how its two discovery modes differ, what a clean result does and does not prove, and how retention and cost work.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Amazon Macie is an AWS service that inventories Amazon S3 general purpose buckets, flags bucket security and access-control issues, and discovers sensitive data inside S3 objects. Its documented scope stops there: it is not a general scanner for databases, file servers, or other data stores. Two details matter most for security teams. A Macie result set with no findings does not prove that every object was analyzed, and Macie keeps its own object-level discovery results for only 90 days unless you export them.

What Macie monitors

Macie works on two kinds of material in an AWS account. The first is the bucket inventory: Macie evaluates S3 general purpose buckets for security and access-control problems, and it can generate policy findings when a configuration change creates a potential security or privacy concern. The second is the object content: Macie analyzes objects to find sensitive data, using machine learning and pattern matching for detection.

Enablement is Region-specific. You enable Macie for each Region where you want it to work, and it covers the S3 general purpose buckets in that Region. A second Region needs its own enablement and its own settings.

Two discovery approaches

Macie offers two ways to find sensitive data. They answer different questions, and they are priced differently, so it helps to understand both before you turn anything on.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
BookFactory Security Incident Report Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • This BookFactory log book is for security guards in any sector or business. You can report location, circumstances and report number.
  • There are spaces to log the individual's names address, description and other identifying information. There are also spaces to note others involved, notes, and vehicle information if one was involved
  • Wire-O, 100 Pages, Dimensions 3.5" x 5.25"
  • Reorder SKU: LOG-100-M3CW-PP(Security-Report)

Automated sensitive data discovery

Automated discovery runs continuously. It evaluates the bucket inventory and uses sampling techniques to select representative objects for analysis. This gives you broad, ongoing visibility across the buckets in a Region without you choosing individual objects. Administrators can adjust its scope, including excluding specific buckets, and organization administrators have account-level controls. AWS states that results typically become reviewable within 48 hours of enablement, depending on account settings and how far analysis has progressed. Treat that as a typical expectation, not a completion deadline.

Because the method is sample-based, automated discovery should be described as broad visibility. It is not an object-by-object guarantee.

Rank #2
BookFactory Security Pass Down Log Book, Wire-O, 100 Pages
  • Made in USA - Proudly produced in Ohio by a Veteran-owned business
  • Comprehensive Coverage: This BookFactory log book includes essential fields such as post/shift, time of change, date, weather conditions, and a designated space for detailed notes. This ensures that all relevant information is captured and easily accessible.
  • Sturdy Cover: The trans-lux cover protects the log book from wear and tear, ensuring its longevity and maintaining the integrity of your recorded data.
  • Essential Security Tool: This log book is an indispensable tool for any organization that values security and accountability. It helps to prevent misunderstandings, improve communication, and ensure a smooth transition between shifts.
  • Wire-O with Trans-lux cover, 100 Pages, Dimensions 8.5" x 11" - (Security-Pass-Down) Reorder SKU: LOG-100-7CW-PP(Security-Pass-Down)

Sensitive data discovery jobs

A discovery job is a defined, user-controlled analysis. You choose the buckets directly or select buckets that meet criteria you define, and you decide whether the job runs once or on a schedule. You can refine what the job looks for with managed data identifiers, custom data identifiers, and allow lists. The job workflow shows an estimated cost before you submit it. The final charge depends on how much data is analyzed and on other applicable AWS charges.

Jobs suit a defined investigation, a compliance review of specific buckets, or a recurring scan of a known set of buckets. They still depend on supported objects and on the detection criteria you configure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the two compare

Factor Automated sensitive data discovery Sensitive data discovery job
Coverage strategy Representative sampling across the bucket inventory Analysis of the buckets and criteria you select
Control Service-selected objects that run continuously; you set scope and exclusions You set buckets, identifiers, allow lists, and whether the job runs once or on a schedule
Cost planning Ongoing charges across buckets evaluated, objects monitored, and data analyzed Charges for the data the job analyzes, plus any related S3 request charges
Free trial Included within the trial, subject to the stated terms and cap Not included in the trial
Best fit Broad, continuous visibility Defined reviews and recurring targeted scans

The two are complementary rather than substitutes. Many teams use automated discovery to see where sensitive data may sit and jobs to examine specific buckets more closely.

Findings and discovery results are different records

Macie produces two separate outputs, and an audit trail needs both to be understood correctly.

Record What it shows Retention in Macie
Policy findings Potential security or privacy issues with an S3 bucket’s configuration 90 days
Sensitive data findings Sensitive data detected in a specific object: category or type, occurrence count, affected bucket and object, and detection time. The sensitive data itself is not included. 90 days
Sensitive data discovery results Object-level analysis records, including objects with detections, objects with no detections, and objects Macie could not analyze 90 days in Macie; longer retention requires an S3 repository

Findings can be filtered, grouped, sorted, and managed with suppression rules. Suppression changes what you see in the findings list; it does not change what Macie analyzed. Discovery results are the record that tells you what was examined, which is why they matter for investigations.

Setting up Macie

AWS’s getting-started process follows a short sequence. The order below reflects that process.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Confirm that the IAM identity you use has the permissions required to enable Macie. Macie needs permission to create its service-linked role.
  2. Select the AWS Region where you want Macie to work. Each Region is enabled separately.
  3. Enable Macie in that Region. Macie can begin building the S3 bucket inventory within minutes.
  4. Review the permissions of the service-linked role, if your governance process requires it.
  5. Decide whether you need to keep discovery results beyond 90 days. If you do, configure an S3 repository for them. AWS recommends doing this within 30 days of enabling the service, because Macie’s own retention for those results is limited to 90 days.

The repository is configured per Region, and it requires an S3 bucket and a KMS key for encryption. Plan the bucket and key before you enable the repository, and make sure the account that owns them can read and write the results.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What “no findings” does and does not mean

A clean result set is only as complete as the analysis behind it. Macie analyzes only objects it can access and that fall within its supported storage classes and file or storage formats. AWS’s supported-format list includes common document types such as PDF, Microsoft Excel, and Word, along with other supported types. Check that list against the formats in your own buckets rather than assuming full coverage.

Several conditions can leave objects unanalyzed:

  • The object is in an S3 storage class Macie does not support.
  • The file or storage format is not on the supported list.
  • Macie lacks permission to read the object, or the object has another issue that prevents analysis.
  • The object falls outside the scope of automated discovery’s sample, or outside a job’s bucket selection.

This is why discovery results list unanalyzed objects separately. Review that list before concluding that a bucket is clean.

What drives cost

AWS prices Macie on three usage dimensions:

  • Buckets evaluated for inventory and security monitoring.
  • Objects monitored for automated sensitive data discovery.
  • Data analyzed for sensitive data discovery, whether through automated discovery or through jobs.

Related AWS usage can add to the bill. S3 requests, and customer-managed KMS key use where your configuration relies on it, are charged separately from Macie.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Item Stated terms in AWS’s Macie pricing material (checked 7 October 2026)
Free trial 30 days from first enablement in a Region. Automated discovery is included within the trial, subject to the stated terms and cap. Targeted discovery jobs are not included.
Trial analysis amount The pricing page states 150 GB per account of data inspected for automated discovery within the 30-day trial.
Monthly free tier 1 GB per month of analyzed S3 object data for discovery, subject to account and consolidated-billing terms.
Published example $151.50 per month, US East (Northern Virginia), with 15 buckets, 10 million supported objects, and 150 GB analyzed for automated discovery. This is an illustration under those assumptions, not a quote or a general rate.
Per-unit rates Not stated in the material reviewed; check the regional rates on the AWS pricing page for your Region.

Because the example is dated and Region-specific, build your own estimate with the bucket count, the number of supported objects, and the volume you expect to analyze. Run the job estimate before submitting any job so the figure reflects your actual data.

Choosing an approach

Use this framework to decide where to start:

  • You need continuous visibility across many buckets and accept sampling: start with automated discovery and review its scope and exclusions.
  • You have a specific set of buckets to examine or a compliance question with a defined boundary: run a discovery job with explicit bucket selection, identifiers, and, if needed, a schedule.
  • You must keep an object-level record for longer than 90 days: configure an S3 repository for discovery results before the first analysis you need to keep.
  • Your data lives outside S3 general purpose buckets: Macie does not cover it, so plan a separate control for that store.

Common pitfalls

  • Assuming a bucket is clean because findings are empty, without checking the unanalyzed objects in discovery results.
  • Letting discovery results age out of Macie’s 90-day window with no repository configured.
  • Treating sampled automated results as a full inventory of sensitive data.
  • Estimating cost from the example price instead of your own bucket, object, and data volumes.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.