Event ID 4728: Member added to global group
- Event ID
- 4728
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4728 means
Event 4728 is written on the domain controller that processed the change when an account or group is added to a security-enabled global group. Global groups are domain groups — Domain Admins, Group Policy Creator Owners and most role groups created by administrators — so this event never appears on workstations or member servers. Local and domain local groups use 4732, universal groups 4756.
The fields are the same as in 4732: TargetUserName/TargetSid identify the group, MemberName (distinguished name) and MemberSid the new member, and Subject* who made the change. One event is logged per added member, usually alongside an empty 4737.
Additions to Domain Admins and other tier-0 global groups are among the highest-value alerts in Active Directory. Build the alert on the group SID (RID 512 for Domain Admins) rather than the name, which is localized and can be renamed.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Only generated on domain controllers, on the DC where the change was written. Collect the Security log from every DC to see all group changes.
Key fields
| Field | What it tells you | ||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MemberName | Distinguished name of the added member, e.g. CN=jdoe,OU=Staff,DC=contoso,DC=local. | ||||||||||||
| MemberSid | SID of the added member. | ||||||||||||
| TargetUserName | Name of the global group that received the member. | ||||||||||||
| TargetDomainName | Domain of the group. | ||||||||||||
| TargetSid | SID of the group. The last component (RID) identifies well-known domain groups regardless of their display name.
| ||||||||||||
| SubjectUserName | Account that added the member. | ||||||||||||
| SubjectDomainName | Domain of the subject. | ||||||||||||
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624 to find the source host. | ||||||||||||
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Identity management and HR-driven provisioning adding users to role groups.
- Administrators granting access through application or department groups.
- Temporary membership granted by privileged access management tools, followed later by 4729.
What attackers do that produces it
- Privilege escalation or persistence by adding a controlled account to Domain Admins or another privileged global group.
- Adding a newly created account (4720) to a privileged group within minutes of its creation.
- Adding accounts to groups that hold delegated rights on AD objects, Group Policy or servers, which is quieter than Domain Admins.
Investigation tips
- Alert on additions to privileged groups by SID and verify each against an approved change.
- Check whether the member was created recently (4720) and what it did next (4624, 4672, 4769).
- Pivot on SubjectLogonId and the DC's 4624 events to find the host the change was made from.
- Look for a later 4729 removing the same member — brief membership is a common way to avoid detection.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowA Member Was Added to a Security-Enabled Global GroupRule by Alexandr Yampolskyi, SOC Prime, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 4729Member removed from global groupSecurity
- 4727Global group createdSecurity
- 4737Global group changedSecurity
- 4732Member added to local groupSecurity
- 4756Member added to universal groupSecurity
- 4720User account createdSecurity
- 4624Successful logonSecurity
- 4672Special privileges assignedSecurity
- 5136AD object modifiedSecurity