DeleteUserPermissionsBoundary
DeleteUserPermissionsBoundary
Event
Removes the boundary association from the specified IAM user; it does not delete the managed policy used as the boundary.
Security Context
An unauthorized boundary change can enable privilege escalation when it removes restrictions on permissions granted elsewhere. Boundaries do not grant permissions themselves; other applicable controls and explicit denies still matter. Approved boundary maintenance is also normal. The T1548 mapping is contextual to abuse of this elevation control, not proof from the API name alone.
Evaluate resource-based grants separately: within the same account, direct grants to an IAM user ARN or role-session ARN can escape a boundary’s implicit deny. Explicit denies still apply. Do not treat the boundary as an absolute limit on every grant path.
Log Source
AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteUserPermissionsBoundary. Include IAM global-service events in your collection. Check errorCode and errorMessage; a recorded attempt is not necessarily a completed change, and responseElements: null alone does not establish failure.
Key Fields
| Field | Investigation value |
|---|---|
userIdentity | Caller and session context; compare with the target and approved automation. |
requestParameters.userName | Target IAM user, interpreted with the account identity. |
| Prior boundary | Not supplied in this request; recover its ARN and policy version from historical configuration or earlier events. |
eventTime, recipientAccountId, requestID, eventID | Timeline, account, and correlation identifiers. |
sourceIPAddress, userAgent | Supporting context, not proof of identity or malicious intent. |
errorCode, errorMessage | Failed requests must be distinguished from successful changes. |
What to Investigate
- Confirm the outcome and match the caller, target, and timing to an approved change. Review failed attempts separately.
- Recover the previous boundary and its policy document at the event time. Confirm that the association was removed; the underlying managed policy can remain attached elsewhere.
- Compare effective access before and after the change using the target’s grants, applicable SCPs, session policies, resource policies, and denies. Identify concrete newly allowed actions rather than assuming administrator access.
- Correlate the companion boundary operation and subsequent target activity. Distinguish the calling identity from the target user. A policy change does not create credentials or prove that an attacker can still authenticate.
Sample Event
Synthetic suspicious scenario. Draco removes the boundary from draco. The record contains neither the previous boundary nor the target’s remaining grants; privilege escalation requires those additional facts.
This is an illustrative CloudTrail-shaped record. Exact field presence and policy-document serialization have not been verified against a captured event.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:39:55Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteUserPermissionsBoundary", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "draco" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100000010", "eventID": "90000000-0000-4000-8000-000100000011", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1548 — Abuse Elevation Control Mechanism — Adversaries may circumvent mechanisms designed to control privilege elevation to gain higher-level permissions. Most modern systems contain native elevation control mechanisms that are intended to limit privileges that a user can perform on a machine. Authorization has to be granted to specific u...