RemoveAccountFromOrganization
RemoveAccountFromOrganization
Event
The management account removes the specified member account. This is not account closure and cannot be used to remove the management account. Standalone-account requirements and delegated-administrator status can prevent completion.
Security Context
Unauthorized departure can remove organization policy constraints and disrupt centralized oversight (T1685). Approved divestiture or account migration is also legitimate. Loss of SCP constraints does not grant permissions by itself: IAM and other applicable controls still matter. Verify each security service’s post-departure state instead of assuming all monitoring stopped.
The mapping describes a possible adversarial sequence, not a verdict on every occurrence.
Log Source
CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: RemoveAccountFromOrganization. Check collection scope and retention before interpreting absent records. Search the account that made the API call. Correlate the separate AccountDepartedOrganization membership event in management-account Event history; LEFT and REMOVED distinguish departure methods.
Key Fields
| Field | Investigation use |
|---|---|
requestParameters.accountId | Member being removed; distinct from the management-account caller. |
userIdentity, eventTime, sourceIPAddress, userAgent | Attribute the caller and correlate with approved work. |
recipientAccountId, awsRegion | Account and recording Region; distinguish caller, target, and resource scope. |
errorCode, errorMessage | Check request failures and confirm resulting state; null response alone is not proof of success. |
What to Investigate
- Confirm approved ownership changes and inspect errors, including standalone-account and delegated-administrator restrictions.
- Verify membership state and correlate the management-account AccountDepartedOrganization record with the API request.
- Recover prior organization policies and assess effective permissions, independent trails, and security-service relationships separately.
- Correlate with LeaveOrganization and subsequent account activity; verify approved governance and monitoring are restored.
Sample Event
Synthetic scenario. A role in management account 555700070007 requests removal of member 555123456789. The assumed-role record does not prove the preceding compromise path or unrestricted subsequent access. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.
{ "eventVersion": "1.09", "userIdentity": { "type": "AssumedRole", "principalId": "AROA0RGACCESS0RG007:draco-org-session", "arn": "arn:aws:sts::555700070007:assumed-role/OrgAccessRole/draco-org-session", "accountId": "555700070007", "accessKeyId": "ASIA0RGACCESSEXAMPLE", "sessionContext": { "sessionIssuer": { "type": "Role", "principalId": "AROA0RGACCESS0RG007", "arn": "arn:aws:iam::555700070007:role/OrgAccessRole", "accountId": "555700070007", "userName": "OrgAccessRole" }, "attributes": { "creationDate": "2026-04-15T19:42:51Z", "mfaAuthenticated": "false" } } }, "eventTime": "2026-04-15T19:46:18Z", "eventSource": "organizations.amazonaws.com", "eventName": "RemoveAccountFromOrganization", "awsRegion": "us-east-1", "sourceIPAddress": "203.0.113.66", "userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6", "requestParameters": { "accountId": "555123456789" }, "responseElements": null, "requestID": "90000000-0000-4000-8000-000110011100", "eventID": "90000000-0000-4000-8000-000110011101", "readOnly": false, "eventType": "AwsApiCall", "managementEvent": true, "recipientAccountId": "555700070007", "eventCategory": "Management", "tlsDetails": { "tlsVersion": "TLSv1.3", "cipherSuite": "TLS_AES_128_GCM_SHA256", "clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com" }}Sources
MITRE ATT&CK Mapping
Tactics: Defense Impairment
- T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...