Event ID 4722: User account enabled
- Event ID
- 4722
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4722 means
Event 4722 is written when a disabled account is enabled. For user accounts it appears on domain controllers (domain accounts) and on member servers and workstations (local accounts); for computer accounts it is only logged on domain controllers. The record is short: Subject* identifies who made the change, Target* identifies the account.
Most 4722 events are part of normal provisioning: accounts created in Active Directory Users and Computers start disabled, so a 4720 is usually followed by a 4722 within seconds. A 4722 on its own, for an account that has been disabled for a long time, is more interesting.
Watch in particular the built-in local Administrator (RID 500) and Guest (RID 501) accounts, which are disabled by default on current Windows versions, and dormant accounts of former employees.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Enabling an account also generates a 4738 (user) or 4742 (computer) whose UserAccountControl field shows the Account Disabled flag being cleared.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that enabled the target account. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624 to find where the change was made from. |
| TargetUserName | Account that was enabled. |
| TargetDomainName | Domain of the enabled account, or the computer name for a local account. |
| TargetSid | SID of the enabled account. A SID ending in -500 is the built-in Administrator, -501 the Guest account. |
Common benign sources
- Part of the normal sequence 4720, 4724, 4722 when administrators create a new account.
- Returning employees or contractors whose accounts are re-enabled by the helpdesk.
- Identity management systems enabling accounts on a start date.
What attackers do that produces it
- Enabling the built-in local Administrator or Guest account to get a known account for persistence or lateral movement.
- Reactivating a dormant or former-employee domain account, which is less likely to be noticed than a new one.
Investigation tips
- Check whether the target account was disabled on purpose (offboarding, security incident) and who re-enabled it.
- Look for 4724 (password reset) and 4738 on the same TargetSid around the same time, then for its next logons (4624).
- Pivot on SubjectLogonId to reconstruct the administrator's session and tooling.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.