Event ID 4720: User account created
- Event ID
- 4720
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4720 means
Event 4720 is written each time a new user object is created. For a local account it is logged on the workstation or server that owns the SAM database; for a domain account it is logged on the domain controller that processed the request. The Subject* fields identify who created the account, the Target* fields identify the new account.
The rest of the record is a snapshot of the initial attributes: SamAccountName, UserPrincipalName, PrimaryGroupId, SidHistory, AllowedToDelegateTo and the SAM account flags in NewUacValue and UserAccountControl. An account created through Active Directory Users and Computers typically starts disabled with no password set (NewUacValue 0x15), so the creation is usually followed within seconds by 4724 (password set), 4722 (enabled) and one or more 4738 events.
Account creation is rare enough that most organizations review every 4720. Pay special attention to local accounts created on servers and workstations, accounts created outside the normal provisioning process, and new accounts that are quickly added to privileged groups (4728, 4732, 4756).
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Logged on domain controllers for domain accounts and on member servers and workstations for local accounts, so local account creation is only visible in the endpoint's own Security log. Several attributes may appear as - when they were not captured, and local accounts show <value not set> for many of them.
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that created the new user. Compare against your list of identity administrators and provisioning service accounts. | ||||||||||||||||
| SubjectDomainName | Domain (or computer name for local accounts) of the creator. | ||||||||||||||||
| SubjectLogonId | Logon session of the creator. Pivot to 4624 with the same TargetLogonId to learn where and how the creator logged on. | ||||||||||||||||
| TargetUserName | Name of the new account. | ||||||||||||||||
| TargetDomainName | Domain of the new account, or the computer name when a local account was created. | ||||||||||||||||
| TargetSid | SID of the new account. Use it to follow the account through later events even if it is renamed (4781). | ||||||||||||||||
| SamAccountName | Pre-Windows 2000 logon name. An empty value or - is abnormal. | ||||||||||||||||
| UserPrincipalName | UPN of a domain account (user@domain). Always - for local accounts. | ||||||||||||||||
| PrimaryGroupId | RID of the primary group. 513 (Domain Users, or Users for local accounts) is normal; anything else deserves a look. | ||||||||||||||||
| NewUacValue | SAM account flags of the new account in hexadecimal (the SAM definition, which differs from the Active Directory userAccountControl bit values). OldUacValue is always 0x0 for new accounts.
| ||||||||||||||||
| UserAccountControl | The same flags rendered as message codes, e.g. %%2080 %%2082 %%2084 for 0x15 (Account Disabled, Password Not Required, Normal Account). | ||||||||||||||||
| SidHistory | Previous SIDs of a migrated account. Should be - for a freshly created account. | ||||||||||||||||
| AllowedToDelegateTo | SPNs the account may delegate to (constrained delegation). Normally - on creation. | ||||||||||||||||
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Helpdesk or identity management systems provisioning new employees, usually from a small set of admin or service accounts.
- Software installers and management agents that create local service accounts.
- Domain controller promotion, migrations and lab builds creating many accounts in a burst.
What attackers do that produces it
- Persistence by creating a local account on a compromised host, often with
net user <name> <password> /addfollowed by adding it to the local Administrators group (4732). - Creating a domain account and adding it to Domain Admins or another privileged group (4728, 4756).
- Account names chosen to blend in, such as look-alikes of service or admin accounts, or names ending in
$to resemble computer accounts.
Investigation tips
- Check whether SubjectUserName is an expected provisioning account and whether the creation matches a ticket or HR onboarding.
- Look for group membership changes for the same TargetSid right after creation (4728, 4732, 4756) and for its first logon (4624).
- Pivot on SubjectLogonId to find the creator's logon (4624) and, if process auditing is on, the process that did it (4688, e.g.
net.exe,net1.exeor PowerShell). - Review the initial attributes for unusual values — non-513 PrimaryGroupId, SidHistory, delegation settings or pre-authentication disabled.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
4 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- Low · 1
- HighHidden Local User CreationRule by Christian Burkard (Nextron Systems), SigmaHQ, DRL 1.1
- HighSuspicious Windows ANONYMOUS LOGON Local Account CreatedRule by James Pemberton / @4A616D6573, SigmaHQ, DRL 1.1
- MediumNew or Renamed User Account with '$' CharacterRule by Ilyas Ochkov, oscd.community, SigmaHQ, DRL 1.1
- LowLocal User CreationRule by Patrick Bareiss, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 4722User account enabledSecurity
- 4724Password reset attemptSecurity
- 4726User account deletedSecurity
- 4738User account changedSecurity
- 4728Member added to global groupSecurity
- 4732Member added to local groupSecurity
- 4756Member added to universal groupSecurity
- 4781Account renamedSecurity
- 4624Successful logonSecurity
- 4688Process creationSecurity