LeaveOrganization
LeaveOrganization
Event
A member account requests its own departure. The management account cannot leave through this operation; an SCP can deny the request. Standalone-account requirements and delegated-administrator status can prevent completion.
Security Context
Unauthorized departure can remove organization policy constraints and disrupt centralized oversight (T1685). Approved divestiture or account migration is also legitimate. Loss of SCP constraints does not grant permissions by itself: IAM and other applicable controls still matter. Verify each security service’s post-departure state instead of assuming all monitoring stopped.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: LeaveOrganization. Check collection scope and retention before interpreting absent records. Search the account that made the API call. Correlate the separate AccountDepartedOrganization membership event in management-account Event history; LEFT and REMOVED distinguish departure methods.
Key Fields
| Field | Investigation use |
|---|---|
userIdentity.accountId, recipientAccountId | Calling member account; this operation has no target-account request field. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approved ownership changes and inspect errors, including standalone-account and delegated-administrator restrictions.
- Verify membership state and correlate the management-account AccountDepartedOrganization record with the API request.
- Recover prior organization policies and assess effective permissions, independent trails, and security-service relationships separately.
- Correlate with RemoveAccountFromOrganization and subsequent account activity; verify approved governance and monitoring are restored.
Sample Event
Synthetic scenario. Draco requests departure from member account 555123456789. No SCP contents or service shutdown is demonstrated. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "IAMUser", "principalId": "AIDADRAC0MALF0YBADGY", "arn": "arn:aws:iam::555123456789:user/draco", "accountId": "555123456789", "accessKeyId": "ASIADRAC0MALF0YEXAMP5", "userName": "draco", "sessionContext": { "attributes": { "creationDate": "2026-04-15T21:42:08Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T22:18:54Z", "eventSource": "organizations.amazonaws.com", "eventName": "LeaveOrganization", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": null, "responseElements": null, "requestID": "90000000-0000-4000-8000-000101001110", "eventID": "90000000-0000-4000-8000-000101001111", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555123456789", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...