Skip to content
Security

Event ID 4732: Member added to local group

A member was added to a security-enabled local groupSecurity event 4732 is logged when a member is added to a security-enabled local group, such as the local Administrators group or a domain local group.
4732
Event ID
4732
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4732 means

Event 4732 is written when an account or group is added to a security-enabled local group. On workstations and member servers that means groups in the local SAM such as Administrators, Remote Desktop Users or Backup Operators. On domain controllers it covers the Builtin groups of the domain (Administrators, Account Operators, Server Operators, Backup Operators…) and domain local groups such as DnsAdmins. Global and universal groups have their own events (4728, 4756).

TargetUserName and TargetSid identify the group, MemberSid the account that was added, and Subject* who made the change. On member servers and workstations, MemberName is usually -, even for domain accounts, so resolve MemberSid instead. One event is logged per added member, typically preceded by an empty 4735.

Adding an account to the local Administrators group is one of the most common persistence and privilege steps after compromise, which makes this event a high-value detection on every endpoint, not only on domain controllers.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Local group changes are only recorded on the machine that owns the group, so collect Security logs from endpoints and servers, not only from domain controllers. Membership pushed by Group Policy (Restricted Groups, Local Users and Groups preferences) also produces 4732 on each target machine.

Key fields

FieldWhat it tells you
MemberSidSID of the added account or group. The reliable field on workstations and member servers.
MemberNameDistinguished name of the added member when available (e.g. CN=jdoe,CN=Users,DC=contoso,DC=local). Usually - for local groups on non-DC machines.
TargetUserNameName of the group that received the new member, e.g. Administrators.
TargetDomainNameDomain of the group — Builtin for built-in local groups, the computer name for other local groups, the domain for domain local groups.
TargetSidSID of the group. Well-known Builtin SIDs make filtering language-independent.
ValueMeaning
S-1-5-32-544Administrators.
S-1-5-32-548Account Operators.
S-1-5-32-549Server Operators.
S-1-5-32-551Backup Operators.
S-1-5-32-555Remote Desktop Users.
S-1-5-32-562Distributed COM Users.
S-1-5-32-580Remote Management Users (WinRM).
SubjectUserNameAccount that added the member.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624 and 4688.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Group Policy (Restricted Groups or Group Policy Preferences) enforcing local Administrators membership at each refresh.
  • IT staff granting local admin or Remote Desktop rights on a specific machine.
  • Software installation adding service accounts to local groups.

What attackers do that produces it

  • Persistence or privilege escalation by adding a controlled account to local Administrators, e.g. net localgroup administrators <user> /add.
  • Adding an account to Remote Desktop Users or Remote Management Users to enable RDP or WinRM access for lateral movement.
  • On domain controllers, adding accounts to Builtin Administrators, Backup Operators or DnsAdmins, which lead to domain compromise.

Investigation tips

  • Resolve MemberSid and check whether the member is new (4720), expected in that group, and how it is used afterward (4624, 4672).
  • Pivot on SubjectLogonId to find the logon session and command (4624, 4688) that performed the change.
  • Check whether the matching 4733 removal appears later — short-lived membership is a common way to hide.
  • Distinguish Group Policy re-applying membership (subject is the computer account, periodic) from interactive changes.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guidePrivileged group changes: Event IDs 4732, 4728 and 4756

Sources and further reading