EnableServiceAccount
EnableServiceAccount
Event
Re-enables a service account so it can be used again subject to its current credentials, permissions, and applicable controls. This is not recovery of a deleted account.
Security Context
Unauthorized reactivation can support account manipulation (T1098). Enabling the account does not recreate deleted keys or restore revoked IAM grants; independently disabled or expired credentials require separate inspection.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.EnableServiceAccount. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Establish why and when the account was disabled and whether reactivation was approved.
- Inspect current keys, impersonation grants, attached workloads, and effective permissions.
- Confirm enabled state and subsequent authentication/API use; do not infer a specific prior incident or immediate workload recovery.
Sample Event
Synthetic scenario. The example enables phoenix-backup. Its earlier disablement reason, key state, role history, and later use are not shown.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.enable invocation-id/90000000000000000000001111110000 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T15:41:33.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.EnableServiceAccount", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000010", "permission": "iam.serviceAccounts.enable", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/100000000000000000010", "type": "iam.googleapis.com/ServiceAccount" } } ], "resourceName": "projects/-/serviceAccounts/100000000000000000010", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.EnableServiceAccountRequest", "name": "projects/fantasticlogs-prod/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com" }, "response": { "@type": "type.googleapis.com/google.protobuf.Empty" } }, "insertId": "evt001111110000", "resource": { "type": "service_account", "labels": { "email_id": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000010" } }, "timestamp": "2026-04-15T15:41:33.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T15:41:33.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098 — Account Manipulation — Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include accoun...