LoFP LoFP / google workspace admin roles may be deleted by system administrators. verify that the configuration change was expected. exceptions can be added to this rule to filter expected behavior.

Techniques

Sample rules

Google Workspace Admin Role Deletion

Description

Detects when a custom admin role is deleted. An adversary may delete a custom admin role in order to impact the permissions or capabilities of system administrators.

Detection logic

event.dataset:google_workspace.admin and event.provider:admin and event.category:iam and event.action:DELETE_ROLE