Skip to content

LeaveOrganization

AWS

LeaveOrganization

service: AWS - Organizations
techniques:

Event

A member account requests its own departure. The management account cannot leave through this operation; an SCP can deny the request. Standalone-account requirements and delegated-administrator status can prevent completion.

Security Context

Unauthorized departure can remove organization policy constraints and disrupt centralized oversight (T1685). Approved divestiture or account migration is also legitimate. Loss of SCP constraints does not grant permissions by itself: IAM and other applicable controls still matter. Verify each security service’s post-departure state instead of assuming all monitoring stopped.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: LeaveOrganization. Check collection scope and retention before interpreting absent records. Search the account that made the API call. Correlate the separate AccountDepartedOrganization membership event in management-account Event history; LEFT and REMOVED distinguish departure methods.

Key Fields

FieldInvestigation use
userIdentity.accountId, recipientAccountIdCalling member account; this operation has no target-account request field.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approved ownership changes and inspect errors, including standalone-account and delegated-administrator restrictions.
  2. Verify membership state and correlate the management-account AccountDepartedOrganization record with the API request.
  3. Recover prior organization policies and assess effective permissions, independent trails, and security-service relationships separately.
  4. Correlate with RemoveAccountFromOrganization and subsequent account activity; verify approved governance and monitoring are restored.

Sample Event

Synthetic scenario. Draco requests departure from member account 555123456789. No SCP contents or service shutdown is demonstrated. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T21:42:08Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:18:54Z",
"eventSource": "organizations.amazonaws.com",
"eventName": "LeaveOrganization",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": null,
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000101001110",
"eventID": "90000000-0000-4000-8000-000101001111",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.