Policy: AmazonMacieServiceRolePolicy ARN: arn:aws:iam::aws:policy/aws-service-role/AmazonMacieServiceRolePolicy Allowed Actions Actions Services iam:ListAccountAliases iam logs:CreateLogGroup logs logs:CreateLogStream logs logs:DescribeLogStreams logs logs:PutLogEvents logs organizations:DescribeAccount organizations organizations:ListAccounts organizations s3:GetAccountPublicAccessBlock s3 s3:GetBucketAcl s3 s3:GetBucketLocation s3 s3:GetBucketLogging s3 s3:GetBucketPolicy s3 s3:GetBucketPolicyStatus s3 s3:GetBucketPublicAccessBlock s3 s3:GetBucketTagging s3 s3:GetBucketVersioning s3 s3:GetBucketWebsite s3 s3:GetEncryptionConfiguration s3 s3:GetLifecycleConfiguration s3 s3:GetObject s3 s3:GetObjectAcl s3 s3:GetObjectTagging s3 s3:GetReplicationConfiguration s3 s3:ListAllMyBuckets s3 s3:ListBucket s3