DeleteUserPolicy
DeleteUserPolicy
Event
Deletes an inline policy embedded in the target user. Managed policies, group policies, and other applicable controls are separate. The request does not reveal the deleted policy’s statements.
Security Context
Unauthorized removal of a restrictive policy may support account manipulation (T1098); removing an allow may reduce access instead. Approved maintenance can look the same. For MFA conditions, aws:MultiFactorAuthPresent is absent in long-term access-key requests. A Bool false condition and BoolIfExists false condition are not equivalent; recover the actual document before judging its protection.
The mapping describes a possible adversarial use, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: iam.amazonaws.com and eventName: DeleteUserPolicy. Review IAM global-service event collection and retention, rather than searching only the workload’s Region. This audit record describes the request, not every downstream access outcome.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.userName | Target user, which may differ from the caller. |
requestParameters.policyName | Name of the deleted inline policy; does not prove MFA enforcement. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute and correlate the caller’s activity. |
recipientAccountId, awsRegion | Account and recording Region; IAM resources are not regional. |
errorCode, errorMessage | Check failures; a null response alone does not prove success. |
What to Investigate
- Confirm authorization, inspect errors, and check for immediate policy replacement.
- Recover the previous policy and inspect its effects, actions, resources, and exact condition operators.
- Evaluate remaining user/group permissions, boundaries, Organizations controls, and relevant resource policies.
- Correlate with DeactivateMFADevice and subsequent activity; policy deletion does not itself remove an enrolled device or demonstrate privileged use.
Sample Event
Synthetic scenario. Draco requests deletion of MFARequired from his user. No policy document is present, so the example does not prove which credentials it restricted or that deletion granted any particular operation. No error fields are shown. Exact CloudTrail serialization and optional identity/session fields have not been validated by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T19:02:11Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:35:02Z", "eventSource": "iam.amazonaws.com", "eventName": "DeleteUserPolicy", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "userName": "draco", "policyName": "MFARequired" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000100000100", "eventID": "90000000-0000-4000-8000-000100000101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "iam.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...