Skip to content
Security

Event ID 4733: Member removed from local group

A member was removed from a security-enabled local groupSecurity event 4733 is logged when a member is removed from a security-enabled local group, such as the local Administrators group or a domain local group.
4733
Event ID
4733
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4733 means

Event 4733 is the counterpart of 4732: it is written when an account or group is removed from a security-enabled local group — local SAM groups on workstations and member servers, Builtin and domain local groups on domain controllers. TargetUserName/TargetSid identify the group, MemberSid the removed member, Subject* who removed it. One event is written per removed member, often preceded by an empty 4735.

Removals are usually routine (cleanup, Group Policy enforcing membership), but two patterns matter in an investigation. First, an add (4732) followed by a removal of the same member minutes or hours later suggests temporary privilege used for a specific action. Second, removal of legitimate administrators from the Administrators group can be a way to lock responders out.

As with 4732, MemberName is usually - on non-DC machines; rely on MemberSid.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Key fields

FieldWhat it tells you
MemberSidSID of the removed account or group.
MemberNameDistinguished name of the removed member when available; usually - on workstations and member servers.
TargetUserNameName of the group the member was removed from.
TargetDomainNameDomain of the group — Builtin, the computer name, or the domain for domain local groups.
TargetSidSID of the group, e.g. S-1-5-32-544 for Administrators.
SubjectUserNameAccount that removed the member.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Group Policy removing members that are not in the approved Restricted Groups list.
  • Access reviews and offboarding removing users from local groups.

What attackers do that produces it

  • Cleaning up after temporary privilege escalation by removing the account added earlier (4732).
  • Removing legitimate administrators from local Administrators to hinder incident response.

Investigation tips

  • Pair each 4733 with the matching 4732 for the same MemberSid and group to measure how long the membership lasted.
  • Check what the member did while it was in the group (4624, 4672, 4688 between the two events).
  • Review removals of administrator accounts that were not initiated by Group Policy or the IAM process.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading