DeactivateMFADevice
DeactivateMFADevice
Event
Deactivates the specified MFA device and disassociates it from the target user. Removing one device does not establish that all MFA devices or policy-enforced MFA requirements are gone.
Security Context
Unauthorized deactivation can weaken authentication and fits T1556.006. Device replacement, recovery, and user offboarding are legitimate uses. A caller changing their own device is not inherently malicious, and possession of credentials alone does not establish permission to deactivate it.
The mapping describes a possible adversarial use, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeactivateMFADevice. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.userName | Target user, distinct from the caller; inspect principal context if omitted. |
requestParameters.serialNumber | The specific device; a virtual device uses an ARN. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the caller’s activity. |
recipientAccountId, awsRegion | Account and recording Region; IAM resources are not regional. |
errorCode, errorMessage | Check failures; a null response alone does not prove success. |
What to Investigate
- Confirm the approved recovery or offboarding request and inspect errors before inferring successful deactivation.
- Check the target’s remaining devices with ListMFADevices and evaluate applicable MFA policies.
- Correlate with DeleteVirtualMFADevice and subsequent enrollment; confirm who controls any replacement.
- Review ConsoleLogin and subsequent API activity. Interpret session MFA metadata in its credential context, not as proof of every authentication path.
Sample Event
Synthetic scenario. Draco requests deactivation of the virtual device draco-totp on his own user. This does not show all devices removed or later password-only access. The CLI user agent does not identify a specific offensive tool. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:11:34Z", "eventSource": "iam.amazonaws.com", "eventName": "DeactivateMFADevice", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "draco", "serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011001000", "eventID": "90000000-0000-4000-8000-000011001001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.