Event ID 4730: Global group deleted
- Event ID
- 4730
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4730 means
Event 4730 is written on the domain controller that processed the request when a security-enabled global group is deleted. It only exists for domain groups. Local and domain local group deletions are reported by 4734, universal group deletions by 4758.
The event identifies the deleted group (TargetUserName, TargetSid) and the account that deleted it (Subject*). All members lose the access granted through the group immediately, and permissions that referenced it are left with an unresolved SID.
Unexpected deletions of groups that control access to applications or data can be sabotage; deletion of a recently created group can be cleanup after misuse.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Only generated on domain controllers.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Name of the deleted group. |
| TargetDomainName | Domain of the group. |
| TargetSid | SID of the deleted group. |
| SubjectUserName | Account that deleted the group. |
| SubjectDomainName | Domain of the subject. |
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Directory cleanup of obsolete role or project groups.
- Decommissioning of applications that used their own groups.
What attackers do that produces it
- Deleting a group used for a backdoor after the operation.
- Deleting groups that grant access to critical systems to disrupt the business.
Investigation tips
- Reconstruct the group's lifetime from 4727, 4728 and 4729 using TargetSid.
- Confirm the deletion with the group owner or change process.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1531 Account Access Removal | Impact |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowA Security-Enabled Global Group Was DeletedRule by Alexandr Yampolskyi, SOC Prime, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.