User Accounts GoogleWorkspace-user_accounts
9 operations, identified by eventName in the audit log.
| eventName | Description |
|---|---|
| any | Source-only rules that filter on applicationName 'user_accounts' without specifying an eventName attribute here. |
| 2sv_disable | A user disabled 2-Step Verification on their account (user self-service action). |
| 2sv_enroll | A user enrolled in 2-Step Verification (user self-service action). |
| password_edit | A user changed their own account password. |
| recovery_email_edit | A user changed their account recovery email address. |
| recovery_phone_edit | A user changed their account recovery phone number. |
| email_forwarding_out_of_domain | A user configured automatic email forwarding to an external address. |
| titanium_enroll | A user enrolled in Google's Advanced Protection Program. |
| titanium_unenroll | A user left Google's Advanced Protection Program. |
any: User Accounts (any event)
#Description
Source-only rules that filter on applicationName 'user_accounts' without specifying an eventName attribute here.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- Reports API: user_accounts activity events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user_accounts
- Reports API activities.list reference https://developers.google.com/workspace/admin/reports/reference/rest/v1/activities/list
2sv_disable: 2-Step Verification Disabled
#Description
A user disabled 2-Step Verification on their account (user self-service action).
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
2sv_enroll: 2-Step Verification Enrolled
#Description
A user enrolled in 2-Step Verification (user self-service action).
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
password_edit: Password Edit
#Description
A user changed their own account password.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
recovery_email_edit: Recovery Email Edit
#Description
A user changed their account recovery email address.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
recovery_phone_edit: Recovery Phone Edit
#Description
A user changed their account recovery phone number.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
email_forwarding_out_of_domain: Email Forwarding Out of Domain
#Description
A user configured automatic email forwarding to an external address.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
gcp::service_name | eq | login.googleapis.com | 1 rule | sigma |
Detection Rules #
View all rules referencing this event →Sigma #
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
titanium_enroll: Advanced Protection Enrolled
#Description
A user enrolled in Google's Advanced Protection Program.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts
titanium_unenroll: Advanced Protection Unenrolled
#Description
A user left Google's Advanced Protection Program.
Fields #
| Name | Description |
|---|---|
applicationName | Reports API applicationName value identifying the GWS service (e.g. admin, login, drive). |
eventName | The specific action within this application. |
actor.email | Email address of the user or administrator who performed the action. |
actor.profileId | Unique Google Workspace profile ID of the actor. |
ipAddress | IP address of the actor at the time of the event. |
parameters | Array of event-specific key-value parameters documenting affected resources. |
References #
- User Accounts Activity Events https://developers.google.com/workspace/admin/reports/v1/appendix/activity/user-accounts