Event ID 4723: Password change attempt
- Event ID
- 4723
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4723 means
Event 4723 records a password change: the caller supplies the old password and a new one. This is the user-driven operation (Ctrl+Alt+Del > Change a password, or a forced change at logon), so Subject* and Target* normally identify the same account. Compare it with 4724, a reset performed by someone else without knowing the old password.
The event has Success and Failure variants. For domain accounts, a failure is logged when the new password does not meet the password policy; a wrong old password shows up on the domain controller as an authentication failure instead (4771 or 4776). For local accounts, a failure is logged both for policy violations and for a wrong old password.
A successful change also updates PasswordLastSet, which is visible in the 4738 that accompanies it.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is audited by default; Failure must be enabled to see rejected attempts.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change request. Normally the same as TargetUserName. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Account whose password was changed. |
| TargetDomainName | Domain of the target account, or the computer name for a local account. |
| TargetSid | SID of the target account. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Users changing their password when it expires or at first logon.
- Failures when a user picks a password that does not meet complexity or history requirements.
What attackers do that produces it
- An attacker who knows a user's current password changes it to lock the legitimate owner out or to keep access after a password spray.
- Password changes for a privileged or service account from an unusual host or at an unusual time.
Investigation tips
- Check that Subject and Target match; if they differ, treat it like a reset (4724) and verify who performed it.
- Correlate with the subject's logon (4624) to find the source host and logon type.
- For service accounts, confirm the change was planned — an unexpected change also breaks services that use the old password.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.