Skip to content
Security

Event ID 4729: Member removed from global group

A member was removed from a security-enabled global groupSecurity event 4729 is logged on a domain controller when a member is removed from a security-enabled global group, such as Domain Admins.
4729
Event ID
4729
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4729 means

Event 4729 is the counterpart of 4728: it is written on the domain controller that processed the change when an account or group is removed from a security-enabled global group. It is only generated on domain controllers; local and domain local groups use 4733, universal groups 4757.

TargetUserName/TargetSid identify the group, MemberName and MemberSid the removed member, Subject* who removed it. One event is logged per removed member, usually alongside an empty 4737.

Pair it with 4728: an add followed by a removal of the same member shortly afterward means someone used temporary privileges, which is normal with just-in-time admin tooling and suspicious without it.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
MemberNameDistinguished name of the removed member.
MemberSidSID of the removed member.
TargetUserNameName of the global group.
TargetDomainNameDomain of the group.
TargetSidSID of the group; RID 512 is Domain Admins.
SubjectUserNameAccount that removed the member.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Role changes and offboarding removing users from groups.
  • Privileged access management tools removing time-bound memberships.

What attackers do that produces it

  • Removing a temporary privileged membership after use to hide it from later group reviews.
  • Removing legitimate administrators from Domain Admins to slow down incident response.

Investigation tips

  • Match each 4729 with the preceding 4728 for the same member and group and review activity in between.
  • Verify removals from privileged groups against change records, especially when the subject is not a known admin.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading