Skip to content
Security

Event ID 4722: User account enabled

A user account was enabledSecurity event 4722 is logged when a user or computer account is enabled. It shows who enabled it and which account, identified by name and SID.
4722
Event ID
4722
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4722 means

Event 4722 is written when a disabled account is enabled. For user accounts it appears on domain controllers (domain accounts) and on member servers and workstations (local accounts); for computer accounts it is only logged on domain controllers. The record is short: Subject* identifies who made the change, Target* identifies the account.

Most 4722 events are part of normal provisioning: accounts created in Active Directory Users and Computers start disabled, so a 4720 is usually followed by a 4722 within seconds. A 4722 on its own, for an account that has been disabled for a long time, is more interesting.

Watch in particular the built-in local Administrator (RID 500) and Guest (RID 501) accounts, which are disabled by default on current Windows versions, and dormant accounts of former employees.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Enabling an account also generates a 4738 (user) or 4742 (computer) whose UserAccountControl field shows the Account Disabled flag being cleared.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that enabled the target account.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624 to find where the change was made from.
TargetUserNameAccount that was enabled.
TargetDomainNameDomain of the enabled account, or the computer name for a local account.
TargetSidSID of the enabled account. A SID ending in -500 is the built-in Administrator, -501 the Guest account.

Common benign sources

  • Part of the normal sequence 4720, 4724, 4722 when administrators create a new account.
  • Returning employees or contractors whose accounts are re-enabled by the helpdesk.
  • Identity management systems enabling accounts on a start date.

What attackers do that produces it

  • Enabling the built-in local Administrator or Guest account to get a known account for persistence or lateral movement.
  • Reactivating a dormant or former-employee domain account, which is less likely to be noticed than a new one.

Investigation tips

  • Check whether the target account was disabled on purpose (offboarding, security incident) and who re-enabled it.
  • Look for 4724 (password reset) and 4738 on the same TargetSid around the same time, then for its next logons (4624).
  • Pivot on SubjectLogonId to reconstruct the administrator's session and tooling.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1078.002 Valid Accounts: Domain AccountsStealth, Persistence, Privilege Escalation, Initial Access
T1078.003 Valid Accounts: Local AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading