Skip to content
Security

Event ID 4726: User account deleted

A user account was deletedSecurity event 4726 is logged when a local or domain user account is deleted, with the subject who deleted it and the removed account's name and SID.
4726
Event ID
4726
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4726 means

Event 4726 is written when a user object is deleted — on domain controllers for domain accounts and on member servers and workstations for local accounts. Subject* identifies who performed the deletion, Target* the deleted account.

Deletion is harder to undo than disabling (4725), so many organizations disable first and delete later. A deletion of an account that was created shortly before (4720) is a classic cleanup pattern: an intruder creates a temporary account, uses it, then removes it. Because the account is gone, TargetSid is the only reliable key to tie the deletion to earlier events for the same account.

Mass deletion of accounts by one subject is also a destructive technique used to deny access to legitimate users and administrators.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Computer account deletions are reported by 4743 (Computer Account Management), not 4726.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that deleted the user.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameName of the deleted account.
TargetDomainNameDomain of the deleted account, or the computer name for a local account.
TargetSidSID of the deleted account. Search older events (4720, 4624, 4728, 4732) for it.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Scheduled cleanup of accounts that were disabled during offboarding.
  • Removal of local accounts by software uninstallers or configuration management.
  • Lab and test environments where accounts are created and deleted routinely.

What attackers do that produces it

  • Removing a temporary backdoor account after use to cover tracks.
  • Deleting many accounts, including administrators, as part of a destructive or ransomware operation.

Investigation tips

  • Search for the TargetSid in earlier 4720, 4624 and group membership events to reconstruct the account's life.
  • Flag deletions of accounts created less than a few days earlier, especially by the same SubjectUserName.
  • Check whether the deleted account was privileged or a service account whose removal could break applications.

MITRE ATT&CK techniques

TechniqueTactics
T1531 Account Access RemovalImpact
T1070.009 Indicator Removal: Clear PersistenceStealth

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading