56 Cloud Identity Free decoy accounts
draft
A user account on a free Cloud Identity seat, named to look high-value — an ex-CFO, an svc-backup identity — left discoverable where an attacker enumerates (the directory, a stale group, an old document ACL) and used by nobody. Any successful login or password-recovery attempt against it is hostile by definition, so an activity rule on its login events can page immediately with no false-positive budget to manage.
Caveats
- A decoy with real group memberships stops being a tripwire and becomes an attack path — grant it nothing, and verify that with GAM rather than assuming.
- The login-alert rule needs only basic activity-rule creation (AND filters, up to 5 conditions), which is available on all editions; only advanced rule features (OR filters, nested conditions, thresholds, custom actions) are gated to Frontline Plus, Enterprise Standard/Plus, Education Plus, Enterprise Essentials Plus, Cloud Identity Premium and Chrome Enterprise Premium.
Setup steps
- open ↗
https://admin.google.com/ac/users · captured 2026-07-15
Directory › Users › Add new userLicense = Cloud Identity Free; long random password; 2SV enrolled but never used
-
Contact sharing on (organization-wide Directory setting; per-OU visibility via custom directories); member of a plausible stale group; listed on an old doc ACL
- open ↗
https://admin.google.com/ac/ax · captured 2026-07-15
Rules › Create rule › Activity- Condition: user log event (login) AND user
decoy- Severity
High- Action
alert center + page
-
gam info user decoy@… gam print groups member decoy@…
Ongoing maintenance
- requires a human Quarterly: keep decoys plausible — aged profile photos, group memberships, mail traffic patterns.
How to verify
-
Attempt a sign-in against a decoy account from a clean browser and confirm the alert fires and routes to the monitored address.
draft v0.1.3 Detect edition All (free seats) policy #30 · #33 ↗