google.iam.admin.v1.DeleteServiceAccount
google.iam.admin.v1.DeleteServiceAccount
Event
Deletes the selected service-account identity. Dependent access can fail, but the event alone does not inventory affected applications or prove an outage. Recovery is generally available within 30 days, subject to documented conditions.
Security Context
Unauthorized deletion can deny access (T1531). A recreated account with the same email is a different identity with a different unique ID. Deletion does not erase historical audit records; retained policy bindings can still identify the deleted principal.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.DeleteServiceAccount. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Confirm unique ID, caller, approval, and whether deletion actually succeeded.
- Inventory dependent workloads and inspect observed access failures rather than assuming every application failed immediately.
- Assess documented undelete eligibility and retained bindings; preserve audit evidence and distinguish restoration from same-name recreation.
Sample Event
Synthetic scenario. The sample deletes bowtruckle-secrets. No specific secrets pipeline, outage, SOC response, or follow-on interference is shown.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.delete invocation-id/90000000000000000000001111110011 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T17:55:08.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.DeleteServiceAccount", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000011", "permission": "iam.serviceAccounts.delete", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/100000000000000000011", "type": "iam.googleapis.com/ServiceAccount" } } ], "resourceName": "projects/-/serviceAccounts/100000000000000000011", "request": { "@type": "type.googleapis.com/google.iam.admin.v1.DeleteServiceAccountRequest", "name": "projects/fantasticlogs-prod/serviceAccounts/bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com" }, "response": { "@type": "type.googleapis.com/google.protobuf.Empty" } }, "insertId": "evt001111110011", "resource": { "type": "service_account", "labels": { "email_id": "bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000011" } }, "timestamp": "2026-04-15T17:55:08.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T17:55:08.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Impact
- T1531 — Account Access Removal — Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users. Accounts may be deleted, locked, or manipulated (ex: changed credentials, revoked permissions for SaaS platforms such as Sharepoint) to remove access to accounts....