Skip to content

DeleteUserPolicy

AWS

DeleteUserPolicy

service: AWS - IAM
techniques:

Event

Deletes an inline policy embedded in the target user. Managed policies, group policies, and other applicable controls are separate. The request does not reveal the deleted policy’s statements.

Security Context

Unauthorized removal of a restrictive policy may support account manipulation (T1098); removing an allow may reduce access instead. Approved maintenance can look the same. For MFA conditions, aws:MultiFactorAuthPresent is absent in long-term access-key requests. A Bool false condition and BoolIfExists false condition are not equivalent; recover the actual document before judging its protection.

The mapping describes a possible adversarial use, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteUserPolicy. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.

Key Fields

FieldInvestigation use
requestParameters.userNameTarget user, which may differ from the caller.
requestParameters.policyNameName of the deleted inline policy; does not prove MFA enforcement.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute and correlate the caller’s activity.
recipientAccountId, awsRegionAccount and recording Region; IAM resources are not regional.
errorCode, errorMessageCheck failures; a null response alone does not prove success.

What to Investigate

  1. Confirm authorization, inspect errors, and check for immediate policy replacement.
  2. Recover the previous policy and inspect its effects, actions, resources, and exact condition operators.
  3. Evaluate remaining user/group permissions, boundaries, Organizations controls, and relevant resource policies.
  4. Correlate with DeactivateMFADevice and subsequent activity; policy deletion does not itself remove an enrolled device or demonstrate privileged use.

Sample Event

Synthetic scenario. Draco requests deletion of MFARequired from his user. No policy document is present, so the example does not prove which credentials it restricted or that deletion granted any particular operation. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T19:02:11Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:35:02Z",
"eventSource": "iam.amazonaws.com",
"eventName": "DeleteUserPolicy",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"userName": "draco",
"policyName": "MFARequired"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000100000100",
"eventID": "90000000-0000-4000-8000-000100000101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Persistence Privilege Escalation

Techniques:
  • T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.