Skip to content

DeactivateMFADevice

AWS

DeactivateMFADevice

service: AWS - IAM
techniques:

Event

Deactivates the specified MFA device and disassociates it from the target user. Removing one device does not establish that all MFA devices or policy-enforced MFA requirements are gone.

Security Context

Unauthorized deactivation can weaken authentication and fits T1556.006. Device replacement, recovery, and user offboarding are legitimate uses. A caller changing their own device is not inherently malicious, and possession of credentials alone does not establish permission to deactivate it.

The mapping describes a possible adversarial use, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeactivateMFADevice. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.

Key Fields

FieldInvestigation use
requestParameters.userNameTarget user, distinct from the caller; inspect principal context if omitted.
requestParameters.serialNumberThe specific device; a virtual device uses an ARN.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the caller’s activity.
recipientAccountId, awsRegionAccount and recording Region; IAM resources are not regional.
errorCode, errorMessageCheck failures; a null response alone does not prove success.

What to Investigate

  1. Confirm the approved recovery or offboarding request and inspect errors before inferring successful deactivation.
  2. Check the target’s remaining devices with ListMFADevices and evaluate applicable MFA policies.
  3. Correlate with DeleteVirtualMFADevice and subsequent enrollment; confirm who controls any replacement.
  4. Review ConsoleLogin and subsequent API activity. Interpret session MFA metadata in its credential context, not as proof of every authentication path.

Sample Event

Synthetic scenario. Draco requests deactivation of the virtual device draco-totp on his own user. This does not show all devices removed or later password-only access. The CLI user agent does not identify a specific offensive tool. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:11:34Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeactivateMFADevice",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "draco",
"serialNumber": "arn:aws:iam::555123456789:mfa/draco-totp"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000011001000",
"eventID": "90000000-0000-4000-8000-000011001001",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1556.006 — Multi-Factor Authentication — Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.