Skip to content

iam.serviceAccounts.implicitDelegation

GCP

iam.serviceAccounts.implicitDelegation

service: GCP - IAM
techniques:

Event

iam.serviceAccounts.implicitDelegation is a permission, not a separate token-exchange API method. This page illustrates GenerateAccessToken with an intermediate service account in delegates.

Security Context

An unauthorized delegation chain can support T1548.005. Every hop needs appropriate authorization; implicit delegation is not an IAM bypass. The sample uses a service-account caller to illustrate the documented A-to-B-to-C permission model.

Log Source

Cloud Audit Logs: iamcredentials.googleapis.com, method GenerateAccessToken. Data Access; enable the relevant IAM Credentials audit logging and check exemptions, routing, retention, and viewer access.

Key Fields

FieldInvestigation value
protoPayload.authenticationInfo, requestMetadataRecorded caller and request context; client text alone does not establish intent.
protoPayload.serviceName, methodName, resourceNameService operation and target scope; permission labels can differ from method names.
protoPayload.authorizationInfo, statusAvailable permission checks and outcome; inspect errors.
protoPayload.request, response, metadata, serviceDataRequested settings, returned metadata, and deltas where present; compare prior state separately.
timestamp, logName, operationTiming, audit category, and operation/session correlation where applicable.

What to Investigate

  1. Confirm the actor, target, outcome, and timing against the approved workflow.
  2. Resolve the original caller, ordered delegates, and terminal target; preserve service-account IDs.
  3. Verify authorization at every hop, using Token Creator bindings or the documented required permissions; do not treat authorizationInfo as a complete policy evaluation trace.
  4. Review scopes, lifetime, and actual downstream use to establish whether the chain increased access.

Sample Event

Synthetic scenario. The example uses pipeline-runner as caller, bowtruckle-secrets as delegate, and phoenix-backup as target. Unverified identityDelegationChain metadata was removed; request.delegates expresses the requested chain.

Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.

{
"protoPayload": {
"@type": "type.googleapis.com/google.cloud.audit.AuditLog",
"authenticationInfo": {
"principalEmail": "pipeline-runner@fantasticlogs-prod.iam.gserviceaccount.com"
},
"requestMetadata": {
"callerIp": "203.0.113.66",
"callerSuppliedUserAgent": "synthetic-client/1.0",
"requestAttributes": {
"time": "2026-04-15T16:42:11.221987654Z",
"auth": {}
},
"destinationAttributes": {}
},
"serviceName": "iamcredentials.googleapis.com",
"methodName": "GenerateAccessToken",
"authorizationInfo": [
{
"resource": "projects/-/serviceAccounts/100000000000000000011",
"permission": "iam.serviceAccounts.implicitDelegation",
"granted": true,
"resourceAttributes": {}
},
{
"resource": "projects/-/serviceAccounts/100000000000000000010",
"permission": "iam.serviceAccounts.getAccessToken",
"granted": true,
"resourceAttributes": {}
}
],
"resourceName": "projects/-/serviceAccounts/100000000000000000010",
"request": {
"@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenRequest",
"name": "projects/-/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"delegates": [
"projects/-/serviceAccounts/bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com"
],
"scope": [
"https://www.googleapis.com/auth/cloud-platform"
],
"lifetime": "3600s"
},
"response": {
"@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenResponse",
"expireTime": "2026-04-15T17:42:11.221987Z"
}
},
"insertId": "evt001111111010",
"resource": {
"type": "service_account",
"labels": {
"email_id": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com",
"project_id": "fantasticlogs-prod",
"unique_id": "100000000000000000010"
}
},
"timestamp": "2026-04-15T16:42:11.421987Z",
"severity": "INFO",
"logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access",
"receiveTimestamp": "2026-04-15T16:42:11.821987Z"
}

Sources

MITRE ATT&CK Mapping

Tactics: Privilege Escalation

Techniques:
  • T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...
Documentation reviewed: October 5, 2026. Samples are synthetic illustrations, not captured production logs or lab-validated fixtures.