Event ID 4726: User account deleted
- Event ID
- 4726
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4726 means
Event 4726 is written when a user object is deleted — on domain controllers for domain accounts and on member servers and workstations for local accounts. Subject* identifies who performed the deletion, Target* the deleted account.
Deletion is harder to undo than disabling (4725), so many organizations disable first and delete later. A deletion of an account that was created shortly before (4720) is a classic cleanup pattern: an intruder creates a temporary account, uses it, then removes it. Because the account is gone, TargetSid is the only reliable key to tie the deletion to earlier events for the same account.
Mass deletion of accounts by one subject is also a destructive technique used to deny access to legitimate users and administrators.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Computer account deletions are reported by 4743 (Computer Account Management), not 4726.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that deleted the user. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Name of the deleted account. |
| TargetDomainName | Domain of the deleted account, or the computer name for a local account. |
| TargetSid | SID of the deleted account. Search older events (4720, 4624, 4728, 4732) for it. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Scheduled cleanup of accounts that were disabled during offboarding.
- Removal of local accounts by software uninstallers or configuration management.
- Lab and test environments where accounts are created and deleted routinely.
What attackers do that produces it
- Removing a temporary backdoor account after use to cover tracks.
- Deleting many accounts, including administrators, as part of a destructive or ransomware operation.
Investigation tips
- Search for the TargetSid in earlier 4720, 4624 and group membership events to reconstruct the account's life.
- Flag deletions of accounts created less than a few days earlier, especially by the same SubjectUserName.
- Check whether the deleted account was privileged or a service account whose removal could break applications.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.