DeleteAccessKey
DeleteAccessKey
Event
Deletes the specified long-term access key; it cannot later be reactivated. This operation does not target an ASIA temporary-session key. If userName is omitted, IAM determines the user from the signing credentials as documented by the API.
Security Context
Unauthorized deletion can disrupt workloads or operators relying on the key (T1531). Planned rotation commonly removes old keys. Other keys, console access, and already-issued sessions require separate assessment. Avoid claiming instantaneous universal lockout from one key operation.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteAccessKey. Check errorCode and errorMessage; a null response alone does not establish success or failure. Include IAM global-service events in collection.
Key Fields
| Field | Investigation value |
|---|---|
requestParameters.accessKeyId | Target long-term key; distinguish it from the caller’s key. |
requestParameters.userName | Key owner when specified; may differ from the caller. |
eventTime, recipientAccountId, eventID, requestID | Timeline and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not a definitive attacker fingerprint. |
What to Investigate
- Confirm the outcome and compare the caller, target, and timing with an approved workflow. Review failed attempts separately.
- Recover ownership, prior status, last-use evidence, and the approved rotation or incident record.
- Correlate CreateAccessKey and dependent workload authentication failures; do not invent a replacement key.
- Check other credentials and issued sessions separately. Deletion cannot be reversed by UpdateAccessKey.
Sample Event
Synthetic scenario. Hermione deletes a key for ron. A replacement key and completed workload migration are not shown.
Exact CloudTrail field presence, redaction, response nesting, and timestamp formatting have not been verified against a captured event. Sensitive values are omitted; examples do not prove authentication or downstream actions.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDAHERM10NE000ADM1N", "arn": "arn:aws:iam::555123456789:user/hermione", "accountId": "555123456789", "accessKeyId": "ASIAHERM10NEEXAMPLE1", "userName": "hermione", "sessionContext": { "attributes": { "creationDate": "2026-04-15T14:02:33Z", "mfaAuthenticated": "true" } } }, "eventTime": "2026-04-15T14:21:09Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteAccessKey", "awsRegion": "us-east-1", "sourceIPAddress": "198.51.100.42", "userAgent": "aws-cli/2.15.30 Python/3.11.6 Linux/5.15.0-1052-aws exe/x86_64.ubuntu.22 prompt/off command/iam.delete-access-key", "requestParameters": { "userName": "ron", "accessKeyId": "AKIAR0NWEA5LEYEXAMP2" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011001010", "eventID": "90000000-0000-4000-8000-000011001011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....