Skip to content
Security

Event ID 4720: User account created

A user account was createdSecurity event 4720 records the creation of a local or domain user account: who created it, the new name and SID, and its initial attributes.
4720
Event ID
4720
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4720 means

Event 4720 is written each time a new user object is created. For a local account it is logged on the workstation or server that owns the SAM database; for a domain account it is logged on the domain controller that processed the request. The Subject* fields identify who created the account, the Target* fields identify the new account.

The rest of the record is a snapshot of the initial attributes: SamAccountName, UserPrincipalName, PrimaryGroupId, SidHistory, AllowedToDelegateTo and the SAM account flags in NewUacValue and UserAccountControl. An account created through Active Directory Users and Computers typically starts disabled with no password set (NewUacValue 0x15), so the creation is usually followed within seconds by 4724 (password set), 4722 (enabled) and one or more 4738 events.

Account creation is rare enough that most organizations review every 4720. Pay special attention to local accounts created on servers and workstations, accounts created outside the normal provisioning process, and new accounts that are quickly added to privileged groups (4728, 4732, 4756).

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Logged on domain controllers for domain accounts and on member servers and workstations for local accounts, so local account creation is only visible in the endpoint's own Security log. Several attributes may appear as - when they were not captured, and local accounts show <value not set> for many of them.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that created the new user. Compare against your list of identity administrators and provisioning service accounts.
SubjectDomainNameDomain (or computer name for local accounts) of the creator.
SubjectLogonIdLogon session of the creator. Pivot to 4624 with the same TargetLogonId to learn where and how the creator logged on.
TargetUserNameName of the new account.
TargetDomainNameDomain of the new account, or the computer name when a local account was created.
TargetSidSID of the new account. Use it to follow the account through later events even if it is renamed (4781).
SamAccountNamePre-Windows 2000 logon name. An empty value or - is abnormal.
UserPrincipalNameUPN of a domain account (user@domain). Always - for local accounts.
PrimaryGroupIdRID of the primary group. 513 (Domain Users, or Users for local accounts) is normal; anything else deserves a look.
NewUacValueSAM account flags of the new account in hexadecimal (the SAM definition, which differs from the Active Directory userAccountControl bit values). OldUacValue is always 0x0 for new accounts.
ValueMeaning
0x1Account disabled.
0x4Password not required.
0x10Normal user account.
0x200Password never expires.
0x2000Trusted for delegation (unconstrained Kerberos delegation).
0x10000Kerberos pre-authentication not required.
0x15Typical value for an account created in Active Directory Users and Computers — disabled, password not required, normal account.
UserAccountControlThe same flags rendered as message codes, e.g. %%2080 %%2082 %%2084 for 0x15 (Account Disabled, Password Not Required, Normal Account).
SidHistoryPrevious SIDs of a migrated account. Should be - for a freshly created account.
AllowedToDelegateToSPNs the account may delegate to (constrained delegation). Normally - on creation.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Helpdesk or identity management systems provisioning new employees, usually from a small set of admin or service accounts.
  • Software installers and management agents that create local service accounts.
  • Domain controller promotion, migrations and lab builds creating many accounts in a burst.

What attackers do that produces it

  • Persistence by creating a local account on a compromised host, often with net user <name> <password> /add followed by adding it to the local Administrators group (4732).
  • Creating a domain account and adding it to Domain Admins or another privileged group (4728, 4756).
  • Account names chosen to blend in, such as look-alikes of service or admin accounts, or names ending in $ to resemble computer accounts.

Investigation tips

  • Check whether SubjectUserName is an expected provisioning account and whether the creation matches a ticket or HR onboarding.
  • Look for group membership changes for the same TargetSid right after creation (4728, 4732, 4756) and for its first logon (4624).
  • Pivot on SubjectLogonId to find the creator's logon (4624) and, if process auditing is on, the process that did it (4688, e.g. net.exe, net1.exe or PowerShell).
  • Review the initial attributes for unusual values — non-513 PrimaryGroupId, SidHistory, delegation settings or pre-authentication disabled.

MITRE ATT&CK techniques

TechniqueTactics
T1136.001 Create Account: Local AccountPersistence
T1136.002 Create Account: Domain AccountPersistence

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

4 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1
  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideEvent ID 4720 explained: detecting rogue account creation in AD

Sources and further reading