Skip to content
Security

Event ID 4730: Global group deleted

A security-enabled global group was deletedSecurity event 4730 is logged on a domain controller when a security-enabled global group is deleted from Active Directory.
4730
Event ID
4730
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4730 means

Event 4730 is written on the domain controller that processed the request when a security-enabled global group is deleted. It only exists for domain groups. Local and domain local group deletions are reported by 4734, universal group deletions by 4758.

The event identifies the deleted group (TargetUserName, TargetSid) and the account that deleted it (Subject*). All members lose the access granted through the group immediately, and permissions that referenced it are left with an unresolved SID.

Unexpected deletions of groups that control access to applications or data can be sabotage; deletion of a recently created group can be cleanup after misuse.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
TargetUserNameName of the deleted group.
TargetDomainNameDomain of the group.
TargetSidSID of the deleted group.
SubjectUserNameAccount that deleted the group.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Directory cleanup of obsolete role or project groups.
  • Decommissioning of applications that used their own groups.

What attackers do that produces it

  • Deleting a group used for a backdoor after the operation.
  • Deleting groups that grant access to critical systems to disrupt the business.

Investigation tips

  • Reconstruct the group's lifetime from 4727, 4728 and 4729 using TargetSid.
  • Confirm the deletion with the group owner or change process.

MITRE ATT&CK techniques

TechniqueTactics
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading