Event ID 4738: User account changed
- Event ID
- 4738
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4738 means
Event 4738 is written each time a user object is changed — on domain controllers for domain accounts and on member servers and workstations for local accounts. One event is logged per change. Subject* identifies who made the change and Target* the account that was changed.
The event lists a fixed set of attributes: logon name, UPN, home directory, logon script, profile path, PasswordLastSet, AccountExpires, PrimaryGroupId, AllowedToDelegateTo, SidHistory, logon hours and the account flags. For domain accounts, an attribute that did not change is shown as -. For local accounts, unchanged attributes carry their current value, which makes it harder to tell what actually changed. A change to an attribute outside this list (for example the account's ACL or its SPNs) still produces a 4738 in which everything is -.
The most valuable part is the account flag change: OldUacValue and NewUacValue hold the SAM account flags before and after, and UserAccountControl lists each flag that was switched on or off. Flags that weaken an account — password not required, password never expires, Kerberos pre-authentication not required, unconstrained delegation, reversible encryption — are frequently set by attackers to prepare credential theft or persistence.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Password changes and resets (4723, 4724), enabling (4722) and disabling (4725) are each accompanied by a 4738. Some changes do not produce 4738 at all; on domain controllers, Audit Directory Service Changes (5136) gives the exact attribute and old/new values. If a user-only flag is set on a computer account it becomes a user-type account and its changes are then reported by 4738 instead of 4742.
Key fields
| Field | What it tells you | ||||||||||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that made the change. | ||||||||||||||||||||||||
| SubjectLogonId | Logon session of the subject; correlate with 4624. | ||||||||||||||||||||||||
| TargetUserName | Account that was changed. | ||||||||||||||||||||||||
| TargetDomainName | Domain of the changed account, or the computer name for a local account. | ||||||||||||||||||||||||
| TargetSid | SID of the changed account. | ||||||||||||||||||||||||
| PasswordLastSet | New password timestamp when the password was changed or reset. | ||||||||||||||||||||||||
| ScriptPath | Logon script path when it was changed. A new logon script on an account is a persistence method. | ||||||||||||||||||||||||
| PrimaryGroupId | New primary group RID if changed. Values other than 513 (Domain Users) are unusual for user accounts. | ||||||||||||||||||||||||
| AllowedToDelegateTo | New list of SPNs for constrained delegation, or <value not set> if the list was cleared. Any change here on a user account deserves review. | ||||||||||||||||||||||||
| SidHistory | New SID history value. Outside a domain migration this should stay -. | ||||||||||||||||||||||||
| OldUacValue | SAM account flags before the change (hexadecimal, SAM definition, not the AD userAccountControl bits). | ||||||||||||||||||||||||
| NewUacValue | SAM account flags after the change. Compare bit by bit with OldUacValue.
| ||||||||||||||||||||||||
| UserAccountControl | One message code per flag that was switched on or off, rendered by Event Viewer as text such as "'Don't Require Preauth' - Enabled". Codes seen in Microsoft's examples include %%2080 (Account Disabled), %%2082 (Password Not Required), %%2084 (Normal Account), %%2087 (Workstation Trust Account) and %%2093 (Trusted For Delegation), each marking the flag as enabled. |
Common benign sources
- Password changes and resets, each producing a 4738 with a new PasswordLastSet.
- Helpdesk and HR systems updating display names, UPNs, home directories or expiration dates.
- Accounts being enabled or disabled, which shows up as an Account Disabled flag change.
What attackers do that produces it
- Disabling Kerberos pre-authentication on a user (flag
0x10000) to AS-REP roast it offline. - Setting Password Never Expires or Password Not Required on a backdoor account.
- Enabling unconstrained or constrained delegation (Trusted For Delegation, AllowedToDelegateTo) on an account the attacker controls.
- Adding SID history of a privileged account, or a logon script that runs attacker code at logon.
Investigation tips
- Decode OldUacValue and NewUacValue and alert on weakening flags (0x4, 0x200, 0x800, 0x2000, 0x10000, 0x40000) being turned on.
- Check the subject — changes to privileged accounts by non-admin or unusual accounts are high priority.
- On domain controllers, pull 5136 for the same object and time to see the exact attributes and old values.
- For pre-authentication or delegation changes, look for follow-up Kerberos activity for the account (4768, 4769).
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
3 SigmaHQ detection rules (release r2026-07-01) target this event.
- High · 2
- Medium · 1
- HighActive Directory User BackdoorsRule by @neu5ron, SigmaHQ, DRL 1.1
- HighWeak Encryption Enabled and KerberoastRule by @neu5ron, SigmaHQ, DRL 1.1
- MediumAddition of SID History to Active Directory ObjectRule by Thomas Patzke, @atc_project (improvements), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.
Related events
- 4720User account createdSecurity
- 4722User account enabledSecurity
- 4723Password change attemptSecurity
- 4724Password reset attemptSecurity
- 4725User account disabledSecurity
- 4742Computer account changedSecurity
- 4765SID History addedSecurity
- 4781Account renamedSecurity
- 4768Kerberos TGT requestedSecurity
- 4769Kerberos service ticket requestedSecurity
- 5136AD object modifiedSecurity