Event ID 4733: Member removed from local group
- Event ID
- 4733
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Groups
- Default logging
- Logged by default
What event 4733 means
Event 4733 is the counterpart of 4732: it is written when an account or group is removed from a security-enabled local group — local SAM groups on workstations and member servers, Builtin and domain local groups on domain controllers. TargetUserName/TargetSid identify the group, MemberSid the removed member, Subject* who removed it. One event is written per removed member, often preceded by an empty 4735.
Removals are usually routine (cleanup, Group Policy enforcing membership), but two patterns matter in an investigation. First, an add (4732) followed by a removal of the same member minutes or hours later suggests temporary privilege used for a specific action. Second, removal of legitimate administrators from the Administrators group can be a way to lock responders out.
As with 4732, MemberName is usually - on non-DC machines; rely on MemberSid.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.
Key fields
| Field | What it tells you |
|---|---|
| MemberSid | SID of the removed account or group. |
| MemberName | Distinguished name of the removed member when available; usually - on workstations and member servers. |
| TargetUserName | Name of the group the member was removed from. |
| TargetDomainName | Domain of the group — Builtin, the computer name, or the domain for domain local groups. |
| TargetSid | SID of the group, e.g. S-1-5-32-544 for Administrators. |
| SubjectUserName | Account that removed the member. |
| SubjectDomainName | Domain or computer name of the subject. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- Group Policy removing members that are not in the approved Restricted Groups list.
- Access reviews and offboarding removing users from local groups.
What attackers do that produces it
- Cleaning up after temporary privilege escalation by removing the account added earlier (4732).
- Removing legitimate administrators from local Administrators to hinder incident response.
Investigation tips
- Pair each 4733 with the matching 4732 for the same MemberSid and group to measure how long the membership lasted.
- Check what the member did while it was in the group (4624, 4672, 4688 between the two events).
- Review removals of administrator accounts that were not initiated by Group Policy or the IAM process.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.