DeleteLoginProfile
DeleteLoginProfile
Event
Deletes the target’s login password. For an IAM user, this removes password-based console sign-in; it does not delete the user or their access keys. The API also supports root-password removal through the documented AssumeRoot workflow.
Security Context
Unauthorized password removal can deny a legitimate user access and fits T1531. Approved offboarding, migration to federation, or centralized root-credential management can also explain the operation. Do not treat this as proof of complete lockout or termination of every existing session.
The mapping describes a possible adversarial use, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteLoginProfile. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.userName | Target user when supplied; omitted-name cases require caller and AssumeRoot context. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the caller’s activity. |
recipientAccountId, awsRegion | Account and recording Region; IAM resources are not regional. |
errorCode, errorMessage | Check failures; a null response alone does not prove success. |
What to Investigate
- Confirm authorization and identify the actual target rather than assuming the caller is the affected user.
- Inspect request errors and verify login-profile state through GetLoginProfile.
- Assess remaining access keys, federation paths, and active sessions separately; password deletion is not a complete access-revocation procedure.
- Correlate with ConsoleLogin and other credential changes, then verify the approved recovery or offboarding outcome.
Sample Event
Synthetic scenario. Draco requests removal of Hermione’s console password. The request does not establish her administrative role, prove all her access stopped, or show that Draco’s access persisted. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:55:48Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteLoginProfile", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "hermione" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000011101000", "eventID": "90000000-0000-4000-8000-000011101001", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....