Event ID 4724: Password reset attempt
- Event ID
- 4724
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4724 means
Event 4724 records a password reset: the subject sets a new password for the target account without supplying the old one. This requires the Reset Password right on the account (or local administrator rights for a local account), so it is normally performed by helpdesk staff, administrators or provisioning tools. Subject* is who reset the password, Target* whose password was reset.
Resets are part of account creation (a new account gets its first password this way, usually next to 4720 and 4722) and of routine helpdesk work. They are also the fastest way for an attacker with delegated rights to take over another account: reset the password, then log on as the target. Tools that abuse Active Directory permissions, such as a delegated "reset password" right on a privileged user, end up in this event.
A failure event is logged when the new password does not meet the password policy; an "access denied" during the reset does not generate a failure 4724. The event is also logged when a computer account password is reset.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is audited by default; Failure must be enabled to see rejected attempts.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that performed the reset. Check it against the expected helpdesk and admin accounts. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Account whose password was reset. |
| TargetDomainName | Domain of the target account, or the computer name for a local account. |
| TargetSid | SID of the target account. |
Common benign sources
- Helpdesk password resets after a user forgets a password or is locked out (often preceded by 4740 and followed by 4767).
- Initial password set during account creation, next to 4720 and 4722.
- Password management tools rotating the local Administrator password or service account passwords.
What attackers do that produces it
- Account takeover by abusing a delegated reset-password permission on another user, including privileged users.
- Resetting the password of a dormant or service account to gain a working credential for lateral movement.
- Mass password resets to lock administrators out during a destructive attack.
Investigation tips
- Verify that SubjectUserName is allowed to reset the target's password and that a ticket or request exists.
- Look for a logon of the TargetUserName shortly after the reset (4624, 4768) from a host the subject controls.
- Resets of privileged accounts (Domain Admins, service accounts) by non-tier-0 accounts need immediate review.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.