Event ID 4725: User account disabled
- Event ID
- 4725
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4725 means
Event 4725 is written when an account is disabled. For user accounts it appears on domain controllers (domain accounts) and on member servers and workstations (local accounts); for computer accounts it is only logged on domain controllers. Subject* identifies who disabled the account, Target* which account was disabled.
Disabling is normally an offboarding or containment action, so most events are expected. It becomes suspicious when administrator, service or security-tool accounts are disabled unexpectedly, or when many accounts are disabled in a short time by a single subject — a pattern seen when intruders try to lock defenders out before deploying ransomware.
A disabled account that is later re-enabled produces 4722; the flag change is also visible in 4738 (users) or 4742 (computers).
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that disabled the target account. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Account that was disabled. |
| TargetDomainName | Domain of the disabled account, or the computer name for a local account. |
| TargetSid | SID of the disabled account. |
Common benign sources
- Offboarding of departing employees and contractors.
- Scripts that disable stale user or computer accounts after a period of inactivity.
- Incident responders disabling compromised accounts.
What attackers do that produces it
- Disabling administrator or backup-operator accounts to hamper recovery before encryption or data destruction.
- Disabling accounts used by security tooling or monitoring so their activity stops.
Investigation tips
- Count 4725 per SubjectUserName over time; a burst of disables by one account is a strong signal.
- Check whether the disabled accounts are privileged or belong to IT and security staff.
- Pivot on SubjectLogonId to find the subject's logon (4624) and processes (4688).
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1531 Account Access Removal | Impact |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.