Suspending or disabling Amazon Macie - Amazon Macie

Suspending or disabling Amazon Macie

You can suspend or disable Amazon Macie in a specific AWS Region by using the Amazon Macie console or the Amazon Macie API. Macie then stops performing all activities for your account in that Region. You aren't charged for using Macie in the Region while it's suspended or disabled.

If you suspend or disable Macie, you can re-enable it at a later time.

Suspending Macie

If you suspend Macie, it retains the session identifier, settings, and resources for your account in the applicable AWS Region. For example, your existing findings remain intact and are retained for up to 30 days. However, when you suspend Macie, it stops performing all activities for your account in the applicable Region. This includes monitoring Amazon S3 buckets and running any sensitive data discovery jobs that are currently in progress. Macie also cancels all of your sensitive data discovery jobs in the Region.

If your account is a Macie administrator account, you must disassociate your account from all of its member accounts before you suspend Macie.

After you suspend Macie, you can re-enable it. You then regain access to your settings and resources in the applicable Region, and Macie resumes its activities for your account in that Region. This includes updating the S3 bucket inventory for your account and monitoring the buckets for security and access control. This doesn't include resuming or restarting your sensitive data discovery jobs. Sensitive data discovery jobs can't be resumed or restarted after they're cancelled.

This topic explains how to suspend Macie by using the Amazon Macie console. If you prefer to do this programmatically, you can use the Account Administration resource of the Amazon Macie API.

To suspend Macie

  1. Open the Macie console at https://console.aws.amazon.com/macie/.

  2. By using the AWS Region selector in the upper-right corner of the page, select the Region in which you want to suspend Macie.

  3. In the navigation pane, choose Settings.

  4. Choose Suspend Macie.

  5. When prompted for confirmation, enter Suspend, and then choose Suspend.

To suspend Macie in multiple Regions, sign in to each additional Region, and then suspend Macie in the Region.

Disabling Macie

When you disable Macie, Macie stops performing all activities for your account in the applicable AWS Region. This includes monitoring Amazon S3 buckets and running any sensitive data discovery jobs that are currently in progress. Macie also deletes all the existing settings and resources that it stores or maintains for your account in the applicable Region, including your findings and sensitive data discovery jobs. Resources that you stored or published to other AWS services remain intact and aren't affected—for example, sensitive data discovery results in Amazon S3 and finding events in Amazon EventBridge.

Warning

If you disable Macie, you also permanently delete all of your existing findings, sensitive data discovery jobs, and custom data identifiers, and all other resources that Macie stores or maintains for your account in the applicable Region. These resources can't be recovered after they're deleted. To keep these resources and only pause your use of Macie, suspend Macie instead of disabling it.

If you want to disable Macie and your account is a Macie member account in an organization, you must disassociate your account from its Macie administrator account before you disable Macie. If your account is a Macie administrator account, you must disassociate your account from all of its member accounts before you disable Macie.

This topic explains how to disable Macie by using the Amazon Macie console. If you prefer to do this programmatically, you can use the Account Administration resource of the Amazon Macie API.

To disable Macie

  1. Open the Macie console at https://console.aws.amazon.com/macie/.

  2. By using the AWS Region selector in the upper-right corner of the page, select the Region in which you want to disable Macie.

  3. In the navigation pane, choose Settings.

  4. Choose Disable Macie.

  5. When prompted for confirmation, enter Disable, and then choose Disable.

To disable Macie in multiple Regions, sign in to each additional Region, and then disable Macie in the Region.