Skip to content
Security

Event ID 4728: Member added to global group

A member was added to a security-enabled global groupSecurity event 4728 is logged on a domain controller when a member is added to a security-enabled global group, such as Domain Admins.
4728
Event ID
4728
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4728 means

Event 4728 is written on the domain controller that processed the change when an account or group is added to a security-enabled global group. Global groups are domain groups — Domain Admins, Group Policy Creator Owners and most role groups created by administrators — so this event never appears on workstations or member servers. Local and domain local groups use 4732, universal groups 4756.

The fields are the same as in 4732: TargetUserName/TargetSid identify the group, MemberName (distinguished name) and MemberSid the new member, and Subject* who made the change. One event is logged per added member, usually alongside an empty 4737.

Additions to Domain Admins and other tier-0 global groups are among the highest-value alerts in Active Directory. Build the alert on the group SID (RID 512 for Domain Admins) rather than the name, which is localized and can be renamed.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers, on the DC where the change was written. Collect the Security log from every DC to see all group changes.

Key fields

FieldWhat it tells you
MemberNameDistinguished name of the added member, e.g. CN=jdoe,OU=Staff,DC=contoso,DC=local.
MemberSidSID of the added member.
TargetUserNameName of the global group that received the member.
TargetDomainNameDomain of the group.
TargetSidSID of the group. The last component (RID) identifies well-known domain groups regardless of their display name.
ValueMeaning
*-512Domain Admins.
*-513Domain Users.
*-515Domain Computers.
*-516Domain Controllers.
*-520Group Policy Creator Owners.
SubjectUserNameAccount that added the member.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624 to find the source host.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Identity management and HR-driven provisioning adding users to role groups.
  • Administrators granting access through application or department groups.
  • Temporary membership granted by privileged access management tools, followed later by 4729.

What attackers do that produces it

  • Privilege escalation or persistence by adding a controlled account to Domain Admins or another privileged global group.
  • Adding a newly created account (4720) to a privileged group within minutes of its creation.
  • Adding accounts to groups that hold delegated rights on AD objects, Group Policy or servers, which is quieter than Domain Admins.

Investigation tips

  • Alert on additions to privileged groups by SID and verify each against an approved change.
  • Check whether the member was created recently (4720) and what it did next (4624, 4672, 4769).
  • Pivot on SubjectLogonId and the DC's 4624 events to find the host the change was made from.
  • Look for a later 4729 removing the same member — brief membership is a common way to avoid detection.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading