Skip to content
Security

Event ID 4713: Kerberos policy changed

Kerberos policy was changedSecurity event 4713 is logged on domain controllers when the domain Kerberos policy (ticket lifetimes, renewal, clock skew) is changed.
4713
Event ID
4713
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Logged by default

What event 4713 means

Event 4713 is written on domain controllers when the Kerberos policy of the domain changes, typically through the Default Domain Policy GPO. The KerberosPolicyChange field lists the parameters that changed with their new and old values, for example KerMaxT (maximum user ticket lifetime) and KerMaxR (maximum user ticket renewal lifetime).

Kerberos policy changes are rare in a stable domain. Lengthening ticket lifetimes extends how long a stolen ticket remains usable, and loosening the policy can make forged or replayed tickets harder to spot.

Because the policy is applied by Group Policy, the subject is often the DC computer account or SYSTEM; the account that edited the GPO shows up in directory change events on the Group Policy object.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.

Only logged on domain controllers.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that applied the change, often the DC computer account.
SubjectLogonIdLogon session of the subject; 0x3e7 for SYSTEM.
KerberosPolicyChangeEach change as Name: new_value (old_value) in hex, or -- when nothing changed. Unchanged parameters are not listed.
ValueMeaning
KerMaxTMaximum lifetime for user ticket (TGT); decimal value / 36000000000 = hours.
KerMaxRMaximum lifetime for user ticket renewal; decimal value / 864000000000 = days.
KerMinTMaximum lifetime for service ticket; decimal value / 600000000 = minutes.
KerProxyMaximum tolerance for computer clock synchronization; decimal value / 600000000 = minutes.
KerOptsEnforce user logon restrictions — 0x80 enabled, 0x0 disabled.

Common benign sources

  • Planned changes to the Default Domain Policy Kerberos settings by domain administrators.
  • Domain functional level upgrades or hardening projects that adjust ticket lifetimes.

What attackers do that produces it

  • Extending ticket and renewal lifetimes in the Default Domain Policy after gaining domain admin rights, so stolen or forged tickets stay valid longer.

Investigation tips

  • Decode the changed parameters and compare with the documented domain baseline.
  • Find the GPO edit with 5136 on the Default Domain Policy object to identify who changed it.
  • Treat any change without a change ticket as suspicious and review recent 4769 anomalies.

MITRE ATT&CK techniques

TechniqueTactics
T1484 Domain or Tenant Policy ModificationDefense Impairment, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading