Skip to content
Security

Event ID 4724: Password reset attempt

An attempt was made to reset an account's passwordSecurity event 4724 is logged when one account resets another account's password without knowing the old one — an administrative action worth reviewing.
4724
Event ID
4724
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4724 means

Event 4724 records a password reset: the subject sets a new password for the target account without supplying the old one. This requires the Reset Password right on the account (or local administrator rights for a local account), so it is normally performed by helpdesk staff, administrators or provisioning tools. Subject* is who reset the password, Target* whose password was reset.

Resets are part of account creation (a new account gets its first password this way, usually next to 4720 and 4722) and of routine helpdesk work. They are also the fastest way for an attacker with delegated rights to take over another account: reset the password, then log on as the target. Tools that abuse Active Directory permissions, such as a delegated "reset password" right on a privileged user, end up in this event.

A failure event is logged when the new password does not meet the password policy; an "access denied" during the reset does not generate a failure 4724. The event is also logged when a computer account password is reset.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is audited by default; Failure must be enabled to see rejected attempts.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that performed the reset. Check it against the expected helpdesk and admin accounts.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount whose password was reset.
TargetDomainNameDomain of the target account, or the computer name for a local account.
TargetSidSID of the target account.

Common benign sources

  • Helpdesk password resets after a user forgets a password or is locked out (often preceded by 4740 and followed by 4767).
  • Initial password set during account creation, next to 4720 and 4722.
  • Password management tools rotating the local Administrator password or service account passwords.

What attackers do that produces it

  • Account takeover by abusing a delegated reset-password permission on another user, including privileged users.
  • Resetting the password of a dormant or service account to gain a working credential for lateral movement.
  • Mass password resets to lock administrators out during a destructive attack.

Investigation tips

  • Verify that SubjectUserName is allowed to reset the target's password and that a ticket or request exists.
  • Look for a logon of the TargetUserName shortly after the reset (4624, 4768) from a host the subject controls.
  • Resets of privileged accounts (Domain Admins, service accounts) by non-tier-0 accounts need immediate review.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading