Insider Threat Matrix™Insider Threat Matrix™
  • ID: AF034.004
  • Created: 05th August 2026
  • Updated: 05th August 2026
  • Contributor: The ITM Team

Disable Cloud and Identity Audit Logging

A subject disables or materially weakens native audit logging within a cloud platform, identity provider, cloud account, subscription, project, tenant, or Software as a Service environment.

 

The subject may disable audit services, remove data-event categories, alter diagnostic settings, disable identity or administrative audit events, exclude resources from monitoring, or change the destination to which native audit records are sent. The activity may affect cloud control-plane actions, resource access, authentication, role assignments, application administration, or other security-relevant events.

 

Investigators should review provider-maintained administrative records, privileged-role activation, configuration changes, logging-resource changes, policy modifications, and discrepancies between native audit sources and exported records.