Skip to content
Security

Event ID 4725: User account disabled

A user account was disabledSecurity event 4725 is logged when a user or computer account is disabled, recording who disabled it and which account was affected.
4725
Event ID
4725
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4725 means

Event 4725 is written when an account is disabled. For user accounts it appears on domain controllers (domain accounts) and on member servers and workstations (local accounts); for computer accounts it is only logged on domain controllers. Subject* identifies who disabled the account, Target* which account was disabled.

Disabling is normally an offboarding or containment action, so most events are expected. It becomes suspicious when administrator, service or security-tool accounts are disabled unexpectedly, or when many accounts are disabled in a short time by a single subject — a pattern seen when intruders try to lock defenders out before deploying ransomware.

A disabled account that is later re-enabled produces 4722; the flag change is also visible in 4738 (users) or 4742 (computers).

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that disabled the target account.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount that was disabled.
TargetDomainNameDomain of the disabled account, or the computer name for a local account.
TargetSidSID of the disabled account.

Common benign sources

  • Offboarding of departing employees and contractors.
  • Scripts that disable stale user or computer accounts after a period of inactivity.
  • Incident responders disabling compromised accounts.

What attackers do that produces it

  • Disabling administrator or backup-operator accounts to hamper recovery before encryption or data destruction.
  • Disabling accounts used by security tooling or monitoring so their activity stops.

Investigation tips

  • Count 4725 per SubjectUserName over time; a burst of disables by one account is a strong signal.
  • Check whether the disabled accounts are privileged or belong to IT and security staff.
  • Pivot on SubjectLogonId to find the subject's logon (4624) and processes (4688).

MITRE ATT&CK techniques

TechniqueTactics
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading