Skip to content

RemoveAccountFromOrganization

AWS

RemoveAccountFromOrganization

service: AWS - Organizations
techniques:

Event

The management account removes the specified member account. This is not account closure and cannot be used to remove the management account. Standalone-account requirements and delegated-administrator status can prevent completion.

Security Context

Unauthorized departure can remove organization policy constraints and disrupt centralized oversight (T1685). Approved divestiture or account migration is also legitimate. Loss of SCP constraints does not grant permissions by itself: IAM and other applicable controls still matter. Verify each security service’s post-departure state instead of assuming all monitoring stopped.

The mapping describes a possible adversarial sequence, not a verdict on every occurrence.

Log Source

CloudTrail management event with eventSource: organizations.amazonaws.com and eventName: RemoveAccountFromOrganization. Check collection scope and retention before interpreting absent records. Search the account that made the API call. Correlate the separate AccountDepartedOrganization membership event in management-account Event history; LEFT and REMOVED distinguish departure methods.

Key Fields

FieldInvestigation use
requestParameters.accountIdMember being removed; distinct from the management-account caller.
userIdentity, eventTime, sourceIPAddress, userAgentAttribute the caller and correlate with approved work.
recipientAccountId, awsRegionAccount and recording Region; distinguish caller, target, and resource scope.
errorCode, errorMessageCheck request failures and confirm resulting state; null response alone is not proof of success.

What to Investigate

  1. Confirm approved ownership changes and inspect errors, including standalone-account and delegated-administrator restrictions.
  2. Verify membership state and correlate the management-account AccountDepartedOrganization record with the API request.
  3. Recover prior organization policies and assess effective permissions, independent trails, and security-service relationships separately.
  4. Correlate with LeaveOrganization and subsequent account activity; verify approved governance and monitoring are restored.

Sample Event

Synthetic scenario. A role in management account 555700070007 requests removal of member 555123456789. The assumed-role record does not prove the preceding compromise path or unrestricted subsequent access. No top-level error is shown. Exact CloudTrail serialization and optional identity/session fields remain unverified by capture.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "AssumedRole",
"principalId": "AROA0RGACCESS0RG007:draco-org-session",
"arn": "arn:aws:sts::555700070007:assumed-role/OrgAccessRole/draco-org-session",
"accountId": "555700070007",
"accessKeyId": "ASIA0RGACCESSEXAMPLE",
"sessionContext": {
"sessionIssuer": {
"type": "Role",
"principalId": "AROA0RGACCESS0RG007",
"arn": "arn:aws:iam::555700070007:role/OrgAccessRole",
"accountId": "555700070007",
"userName": "OrgAccessRole"
},
"attributes": {
"creationDate": "2026-04-15T19:42:51Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T19:46:18Z",
"eventSource": "organizations.amazonaws.com",
"eventName": "RemoveAccountFromOrganization",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"accountId": "555123456789"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000110011100",
"eventID": "90000000-0000-4000-8000-000110011101",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555700070007",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "organizations.us-east-1.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Defense Impairment

Techniques:
  • T1685 — Disable or Modify Tools — Adversaries may disable, degrade, or tamper with security tools or applications (e.g., endpoint detection and response (EDR) tools, intrusion detection systems (IDS), antivirus, logging agents, sensors, etc.) to impair or reduce visibility of defensive capabilities. This may include stopping spec...
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.