Event ID 4713: Kerberos policy changed
- Event ID
- 4713
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 4713 means
Event 4713 is written on domain controllers when the Kerberos policy of the domain changes, typically through the Default Domain Policy GPO. The KerberosPolicyChange field lists the parameters that changed with their new and old values, for example KerMaxT (maximum user ticket lifetime) and KerMaxR (maximum user ticket renewal lifetime).
Kerberos policy changes are rare in a stable domain. Lengthening ticket lifetimes extends how long a stolen ticket remains usable, and loosening the policy can make forged or replayed tickets harder to spot.
Because the policy is applied by Group Policy, the subject is often the DC computer account or SYSTEM; the account that edited the GPO shows up in directory change events on the Group Policy object.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.
Only logged on domain controllers.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that applied the change, often the DC computer account. | ||||||||||||
| SubjectLogonId | Logon session of the subject; 0x3e7 for SYSTEM. | ||||||||||||
| KerberosPolicyChange | Each change as Name: new_value (old_value) in hex, or -- when nothing changed. Unchanged parameters are not listed.
|
Common benign sources
- Planned changes to the Default Domain Policy Kerberos settings by domain administrators.
- Domain functional level upgrades or hardening projects that adjust ticket lifetimes.
What attackers do that produces it
- Extending ticket and renewal lifetimes in the Default Domain Policy after gaining domain admin rights, so stolen or forged tickets stay valid longer.
Investigation tips
- Decode the changed parameters and compare with the documented domain baseline.
- Find the GPO edit with 5136 on the Default Domain Policy object to identify who changed it.
- Treat any change without a change ticket as suspicious and review recent 4769 anomalies.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1484 Domain or Tenant Policy Modification | Defense Impairment, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.