Skip to content
Security

Event ID 4723: Password change attempt

An attempt was made to change an account's passwordSecurity event 4723 is logged when an account attempts to change its own password (knowing the old one). Failure means the new password was rejected.
4723
Event ID
4723
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4723 means

Event 4723 records a password change: the caller supplies the old password and a new one. This is the user-driven operation (Ctrl+Alt+Del > Change a password, or a forced change at logon), so Subject* and Target* normally identify the same account. Compare it with 4724, a reset performed by someone else without knowing the old password.

The event has Success and Failure variants. For domain accounts, a failure is logged when the new password does not meet the password policy; a wrong old password shows up on the domain controller as an authentication failure instead (4771 or 4776). For local accounts, a failure is logged both for policy violations and for a wrong old password.

A successful change also updates PasswordLastSet, which is visible in the 4738 that accompanies it.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is audited by default; Failure must be enabled to see rejected attempts.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change request. Normally the same as TargetUserName.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount whose password was changed.
TargetDomainNameDomain of the target account, or the computer name for a local account.
TargetSidSID of the target account.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Users changing their password when it expires or at first logon.
  • Failures when a user picks a password that does not meet complexity or history requirements.

What attackers do that produces it

  • An attacker who knows a user's current password changes it to lock the legitimate owner out or to keep access after a password spray.
  • Password changes for a privileged or service account from an unusual host or at an unusual time.

Investigation tips

  • Check that Subject and Target match; if they differ, treat it like a reset (4724) and verify who performed it.
  • Correlate with the subject's logon (4624) to find the source host and logon type.
  • For service accounts, confirm the change was planned — an unexpected change also breaks services that use the old password.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading