google.iam.admin.v1.SetIAMPolicy
google.iam.admin.v1.SetIAMPolicy
Event
SetIAMPolicy sets access to the service-account resource. The illustrated policy binds Service Account Token Creator to a principal; this governs impersonation authority, not the service account’s own roles on other resources. Preserve bindings and concurrency/version semantics required by the API.
Security Context
Unauthorized additional cloud roles can support T1098.003. The grant is constrained by policy conditions, organization restrictions, revocation, account state, and the target’s effective authority. It does not establish indefinite access or successful token use.
Log Source
Cloud Audit Logs: iam.googleapis.com, method google.iam.admin.v1.SetIAMPolicy. Admin Activity. Inspect status and resulting state; granted permissions alone do not prove completion.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Compare the complete old/new policy, etag, conditions, and binding delta; identify any removed grants.
- Validate the recipient and effective impersonation permissions plus the target account’s access elsewhere.
- Correlate subsequent token generation and resource access; verify approval and revocation rather than inferring persistence from an email domain.
Sample Event
Synthetic scenario. The example sets a single-binding policy and illustrates an ADD delta for an external principal. It assumes no other prior bindings need preservation; it is not an append-only API request.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "draco@fantasticlogs.cloud" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "google-cloud-sdk gcloud/465.0.0 command/gcloud.iam.service-accounts.add-iam-policy-binding invocation-id/90000000000000000000001111110100 environment/None environment-version/None client-os/LINUX client-os-ver/(5,15,0) client-pltf-arch/x86_64 interactive/False from-script/False python/3.11.6 term/xterm-256color (Linux 5.15.0-1052-aws),gzip(gfe)", "requestAttributes": { "time": "2026-04-15T13:35:42.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iam.googleapis.com", "methodName": "google.iam.admin.v1.SetIAMPolicy", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000001", "permission": "iam.serviceAccounts.setIamPolicy", "granted": true, "resourceAttributes": { "service": "iam.googleapis.com", "name": "projects/-/serviceAccounts/100000000000000000001", "type": "iam.googleapis.com/ServiceAccount" } } ], "resourceName": "projects/-/serviceAccounts/100000000000000000001", "request": { "@type": "type.googleapis.com/google.iam.v1.SetIamPolicyRequest", "resource": "projects/-/serviceAccounts/occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com", "policy": { "version": 1, "bindings": [ { "role": "roles/iam.serviceAccountTokenCreator", "members": [ "user:draco-malfoy-666@gmail.com" ] } ], "etag": "QndTQU1QTEVldGFnMTAxMDA9" } }, "response": { "@type": "type.googleapis.com/google.iam.v1.Policy", "version": 1, "bindings": [ { "role": "roles/iam.serviceAccountTokenCreator", "members": [ "user:draco-malfoy-666@gmail.com" ] } ], "etag": "QndTQU1QTEVldGFnMTAxMDE9" }, "serviceData": { "@type": "type.googleapis.com/google.iam.v1.logging.AuditData", "policyDelta": { "bindingDeltas": [ { "action": "ADD", "role": "roles/iam.serviceAccountTokenCreator", "member": "user:draco-malfoy-666@gmail.com" } ] } } }, "insertId": "evt001111110100", "resource": { "type": "service_account", "labels": { "email_id": "occamy-pipeline@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000001" } }, "timestamp": "2026-04-15T13:35:42.421987Z", "severity": "NOTICE", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Factivity", "receiveTimestamp": "2026-04-15T13:35:42.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Persistence Privilege Escalation
- T1098.003 — Additional Cloud Roles — An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant. For example, adversaries may update IAM policies in cloud-based environments or add a new global administrator in Office 365 environments. With sufficient permi...