Skip to content
Security

Event ID 4727: Global group created

A security-enabled global group was createdSecurity event 4727 is logged on a domain controller when a new security-enabled global group is created in Active Directory.
4727
Event ID
4727
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4727 means

Event 4727 is written on the domain controller that processed the request when a new security-enabled global group is created. It only exists for domain groups, so it never appears on workstations or member servers. Local and domain local groups are reported by 4731, universal groups by 4754.

The event carries the new group's name and SID (TargetUserName, TargetDomainName, TargetSid), its SamAccountName and SidHistory, and the creator in Subject*. Its content is identical to 4731 — only the group scope differs.

A new group grants nothing by itself; follow its SID into membership changes (4728) and into the permissions it receives.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameName of the new group.
TargetDomainNameDomain of the new group.
TargetSidSID of the new group.
SamAccountNamePre-Windows 2000 name of the group.
SidHistoryPrevious SIDs; - for a newly created group. Any value on a new group deserves a look.
SubjectUserNameAccount that created the group.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Administrators or provisioning tools creating role and application groups.
  • Product installations that extend Active Directory with their own groups (Exchange, SCCM and similar).

What attackers do that produces it

  • Creating a group with a harmless-looking name, adding backdoor accounts to it and granting it rights on AD objects or servers.

Investigation tips

  • Verify the creator and whether the group matches a change request.
  • Follow TargetSid into later 4728 events and directory changes (5136) to see what the group was used for.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading