Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF013.005
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Platforms: Oracle Cloud Infrastructure (OCI)Google Cloud Platform (GCP)Microsoft AzureAmazon Web Services (AWS)
  • Contributor: The ITM Team

Delete Cloud User Account

A subject deletes a cloud user account to conceal activity, disrupt attribution, remove access associations, interfere with an investigation, or remove information connected to the account. The deleted identity may be maintained within a cloud platform, cloud identity provider, or Software as a Service application and may include a member or guest account.

 

Deletion may be performed through an administration portal, command-line interface, Application Programming Interface (API), script, or automated identity-lifecycle workflow. Investigators should identify the initiating subject, target identity, deletion method, source address, privileged role used, approval record, and deletion time. They should also preserve and review the account’s prior authentication activity, group and role memberships, authentication methods, licenses, owned resources, mailbox or storage data, and recovery status. Cloud identity platforms retain audit records capable of identifying changes to users and other directory objects, while services such as AWS CloudTrail record account activity involving the creation, modification, or deletion of Identity and Access Management resources.

 

Routine account deletion performed through an authorized offboarding or identity-governance process should not be classified as anti-forensic activity. Classification should require evidence that the deletion was unauthorized, concealed, inconsistent with the approved lifecycle process, or intended to frustrate attribution or preservation.