Skip to content

RemoveUserFromGroup

AWS

RemoveUserFromGroup

service: AWS - IAM
tactics:
techniques:

Event

Removes the specified IAM user from the specified IAM group. The group’s managed and inline policies affect the user through membership. The operation does not create credentials or edit those policy documents.

Security Context

Removing a responder’s needed permissions can hinder access (T1531), but other grants may preserve it. Removing a group containing an explicit Deny can instead increase effective access; assess the actual policy change. Onboarding, role changes, and offboarding are common legitimate reasons. Evaluate Allow and Deny statements together with the user’s other policies, boundary, and applicable organization controls.

Log Source

AWS CloudTrail management event with eventSource: iam.amazonaws.com and eventName: RemoveUserFromGroup. Include IAM global-service events in collection. Check errorCode and errorMessage; responseElements: null alone does not establish failure.

Key Fields

Request fields below are under requestParameters unless another path is shown.

FieldInvestigation value
userIdentityCaller and session context; distinguish the caller from the target.
userNameTarget user; distinguish this from userIdentity, the caller.
groupNameAffected group; inspect actual policies rather than trusting a name such as Administrators.
eventTime, recipientAccountId, eventID, requestIDTimeline, account, and correlation identifiers.
sourceIPAddress, userAgentSupporting context; neither proves malicious intent.
errorCode, errorMessageDistinguish failed attempts from completed changes.

What to Investigate

  1. Confirm the request outcome, calling identity, account, and approved change. A recorded attempt is not necessarily a completed change.
  2. Recover group membership and the group’s managed and inline policy documents at the event time.
  3. Compare effective access before and after the membership change, including remaining grants and removed or added denies. Verify approval and the target’s operational role.
  4. Correlate AddUserToGroup and subsequent user activity. Establish whether sensitive access became available or needed access actually failed.

Sample Event

Synthetic scenario. Draco removes hermione from Administrators. The event does not establish her on-call status, an active incident, or the loss of all administrative access.

This is an illustrative CloudTrail-shaped record. Exact field presence, timestamp formatting, and policy-document serialization have not been verified against a captured event. Preserve raw records before decoding any nested policy documents.

{
"eventVersion": "1.09",
"userIdentity": {
"type": "IAMUser",
"principalId": "AIDADRAC0MALF0YBADGY",
"arn": "arn:aws:iam::555123456789:user/draco",
"accountId": "555123456789",
"accessKeyId": "ASIADRAC0MALF0YEXAMP5",
"userName": "draco",
"sessionContext": {
"attributes": {
"creationDate": "2026-04-15T18:51:02Z",
"mfaAuthenticated": "false"
}
}
},
"eventTime": "2026-04-15T22:41:07Z",
"eventSource": "iam.amazonaws.com",
"eventName": "RemoveUserFromGroup",
"awsRegion": "us-east-1",
"sourceIPAddress": "203.0.113.66",
"userAgent": "aws-cli/1.18.147 Python/3.7.10 Linux/5.4.0-1045-aws botocore/1.18.6",
"requestParameters": {
"groupName": "Administrators",
"userName": "hermione"
},
"responseElements": null,
"requestID": "90000000-0000-4000-8000-000001101010",
"eventID": "90000000-0000-4000-8000-000001101011",
"readOnly": false,
"eventType": "AwsApiCall",
"managementEvent": true,
"recipientAccountId": "555123456789",
"eventCategory": "Management",
"tlsDetails": {
"tlsVersion": "TLSv1.3",
"cipherSuite": "TLS_AES_128_GCM_SHA256",
"clientProvidedHostHeader": "iam.amazonaws.com"
}
}

Sources

MITRE ATT&CK Mapping

Tactics: Impact

Techniques:
  • T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....
Documentation reviewed: September 29, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.