iam.serviceAccounts.implicitDelegation
iam.serviceAccounts.implicitDelegation
Event
iam.serviceAccounts.implicitDelegation is a permission, not a separate token-exchange API method. This page illustrates GenerateAccessToken with an intermediate service account in delegates.
Security Context
An unauthorized delegation chain can support T1548.005. Every hop needs appropriate authorization; implicit delegation is not an IAM bypass. The sample uses a service-account caller to illustrate the documented A-to-B-to-C permission model.
Log Source
Cloud Audit Logs: iamcredentials.googleapis.com, method GenerateAccessToken. Data Access; enable the relevant IAM Credentials audit logging and check exemptions, routing, retention, and viewer access.
Key Fields
| Field | Investigation value |
|---|---|
protoPayload.authenticationInfo, requestMetadata | Recorded caller and request context; client text alone does not establish intent. |
protoPayload.serviceName, methodName, resourceName | Service operation and target scope; permission labels can differ from method names. |
protoPayload.authorizationInfo, status | Available permission checks and outcome; inspect errors. |
protoPayload.request, response, metadata, serviceData | Requested settings, returned metadata, and deltas where present; compare prior state separately. |
timestamp, logName, operation | Timing, audit category, and operation/session correlation where applicable. |
What to Investigate
- Confirm the actor, target, outcome, and timing against the approved workflow.
- Resolve the original caller, ordered delegates, and terminal target; preserve service-account IDs.
- Verify authorization at every hop, using Token Creator bindings or the documented required permissions; do not treat authorizationInfo as a complete policy evaluation trace.
- Review scopes, lifetime, and actual downstream use to establish whether the chain increased access.
Sample Event
Synthetic scenario. The example uses pipeline-runner as caller, bowtruckle-secrets as delegate, and phoenix-backup as target. Unverified identityDelegationChain metadata was removed; request.delegates expresses the requested chain.
Exact optional fields, request/response disclosure, and protobuf serialization require captured-log validation. Names do not establish intent, ownership, or a chain of events. These are illustrative records, not parser fixtures.
{ "protoPayload": { "@type": "type.googleapis.com/google.cloud.audit.AuditLog", "authenticationInfo": { "principalEmail": "pipeline-runner@fantasticlogs-prod.iam.gserviceaccount.com" }, "requestMetadata": { "callerIp": "203.0.113.66", "callerSuppliedUserAgent": "synthetic-client/1.0", "requestAttributes": { "time": "2026-04-15T16:42:11.221987654Z", "auth": {} }, "destinationAttributes": {} }, "serviceName": "iamcredentials.googleapis.com", "methodName": "GenerateAccessToken", "authorizationInfo": [ { "resource": "projects/-/serviceAccounts/100000000000000000011", "permission": "iam.serviceAccounts.implicitDelegation", "granted": true, "resourceAttributes": {} }, { "resource": "projects/-/serviceAccounts/100000000000000000010", "permission": "iam.serviceAccounts.getAccessToken", "granted": true, "resourceAttributes": {} } ], "resourceName": "projects/-/serviceAccounts/100000000000000000010", "request": { "@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenRequest", "name": "projects/-/serviceAccounts/phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com", "delegates": [ "projects/-/serviceAccounts/bowtruckle-secrets@fantasticlogs-prod.iam.gserviceaccount.com" ], "scope": [ "https://www.googleapis.com/auth/cloud-platform" ], "lifetime": "3600s" }, "response": { "@type": "type.googleapis.com/google.iam.credentials.v1.GenerateAccessTokenResponse", "expireTime": "2026-04-15T17:42:11.221987Z" } }, "insertId": "evt001111111010", "resource": { "type": "service_account", "labels": { "email_id": "phoenix-backup@fantasticlogs-prod.iam.gserviceaccount.com", "project_id": "fantasticlogs-prod", "unique_id": "100000000000000000010" } }, "timestamp": "2026-04-15T16:42:11.421987Z", "severity": "INFO", "logName": "projects/fantasticlogs-prod/logs/cloudaudit.googleapis.com%2Fdata_access", "receiveTimestamp": "2026-04-15T16:42:11.821987Z"}Sources
MITRE ATT&CK Mapping
Tactics: Privilege Escalation
- T1548.005 — Temporary Elevated Cloud Access — Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources. Many cloud environments allow administrators to grant user or service accounts permission to request just-in-time access to roles, impersonate other accounts, pass roles onto re...