Event ID 4732: Member added to local group
- Event ID
- 4732
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4732 means
Event 4732 is written when an account or group is added to a security-enabled local group. On workstations and member servers that means groups in the local SAM such as Administrators, Remote Desktop Users or Backup Operators. On domain controllers it covers the Builtin groups of the domain (Administrators, Account Operators, Server Operators, Backup Operators…) and domain local groups such as DnsAdmins. Global and universal groups have their own events (4728, 4756).
TargetUserName and TargetSid identify the group, MemberSid the account that was added, and Subject* who made the change. On member servers and workstations, MemberName is usually -, even for domain accounts, so resolve MemberSid instead. One event is logged per added member, typically preceded by an empty 4735.
Adding an account to the local Administrators group is one of the most common persistence and privilege steps after compromise, which makes this event a high-value detection on every endpoint, not only on domain controllers.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Local group changes are only recorded on the machine that owns the group, so collect Security logs from endpoints and servers, not only from domain controllers. Membership pushed by Group Policy (Restricted Groups, Local Users and Groups preferences) also produces 4732 on each target machine.
Key fields
| Field | What it tells you | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| MemberSid | SID of the added account or group. The reliable field on workstations and member servers. | ||||||||||||||||
| MemberName | Distinguished name of the added member when available (e.g. CN=jdoe,CN=Users,DC=contoso,DC=local). Usually - for local groups on non-DC machines. | ||||||||||||||||
| TargetUserName | Name of the group that received the new member, e.g. Administrators. | ||||||||||||||||
| TargetDomainName | Domain of the group — Builtin for built-in local groups, the computer name for other local groups, the domain for domain local groups. | ||||||||||||||||
| TargetSid | SID of the group. Well-known Builtin SIDs make filtering language-independent.
| ||||||||||||||||
| SubjectUserName | Account that added the member. | ||||||||||||||||
| SubjectDomainName | Domain or computer name of the subject. | ||||||||||||||||
| SubjectLogonId | Logon session of the subject; correlate with 4624 and 4688. | ||||||||||||||||
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Group Policy (Restricted Groups or Group Policy Preferences) enforcing local Administrators membership at each refresh.
- IT staff granting local admin or Remote Desktop rights on a specific machine.
- Software installation adding service accounts to local groups.
What attackers do that produces it
- Persistence or privilege escalation by adding a controlled account to local Administrators, e.g.
net localgroup administrators <user> /add. - Adding an account to Remote Desktop Users or Remote Management Users to enable RDP or WinRM access for lateral movement.
- On domain controllers, adding accounts to Builtin Administrators, Backup Operators or DnsAdmins, which lead to domain compromise.
Investigation tips
- Resolve MemberSid and check whether the member is new (4720), expected in that group, and how it is used afterward (4624, 4672).
- Pivot on SubjectLogonId to find the logon session and command (4624, 4688) that performed the change.
- Check whether the matching 4733 removal appears later — short-lived membership is a common way to hide.
- Distinguish Group Policy re-applying membership (subject is the computer account, periodic) from interactive changes.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumUser Added to Local Administrator GroupRule by Florian Roth (Nextron Systems), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 4733Member removed from local groupSecurity
- 4731Local group createdSecurity
- 4735Local group changedSecurity
- 4728Member added to global groupSecurity
- 4756Member added to universal groupSecurity
- 4720User account createdSecurity
- 4624Successful logonSecurity
- 4672Special privileges assignedSecurity
- 4688Process creationSecurity
- 4799Local group members enumeratedSecurity