Skip to content
Security

Event ID 4738: User account changed

A user account was changedSecurity event 4738 is logged when a user account is modified. Changed attributes carry new values, including account flags such as delegation or pre-auth.
4738
Event ID
4738
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4738 means

Event 4738 is written each time a user object is changed — on domain controllers for domain accounts and on member servers and workstations for local accounts. One event is logged per change. Subject* identifies who made the change and Target* the account that was changed.

The event lists a fixed set of attributes: logon name, UPN, home directory, logon script, profile path, PasswordLastSet, AccountExpires, PrimaryGroupId, AllowedToDelegateTo, SidHistory, logon hours and the account flags. For domain accounts, an attribute that did not change is shown as -. For local accounts, unchanged attributes carry their current value, which makes it harder to tell what actually changed. A change to an attribute outside this list (for example the account's ACL or its SPNs) still produces a 4738 in which everything is -.

The most valuable part is the account flag change: OldUacValue and NewUacValue hold the SAM account flags before and after, and UserAccountControl lists each flag that was switched on or off. Flags that weaken an account — password not required, password never expires, Kerberos pre-authentication not required, unconstrained delegation, reversible encryption — are frequently set by attackers to prepare credential theft or persistence.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Password changes and resets (4723, 4724), enabling (4722) and disabling (4725) are each accompanied by a 4738. Some changes do not produce 4738 at all; on domain controllers, Audit Directory Service Changes (5136) gives the exact attribute and old/new values. If a user-only flag is set on a computer account it becomes a user-type account and its changes are then reported by 4738 instead of 4742.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that made the change.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount that was changed.
TargetDomainNameDomain of the changed account, or the computer name for a local account.
TargetSidSID of the changed account.
PasswordLastSetNew password timestamp when the password was changed or reset.
ScriptPathLogon script path when it was changed. A new logon script on an account is a persistence method.
PrimaryGroupIdNew primary group RID if changed. Values other than 513 (Domain Users) are unusual for user accounts.
AllowedToDelegateToNew list of SPNs for constrained delegation, or <value not set> if the list was cleared. Any change here on a user account deserves review.
SidHistoryNew SID history value. Outside a domain migration this should stay -.
OldUacValueSAM account flags before the change (hexadecimal, SAM definition, not the AD userAccountControl bits).
NewUacValueSAM account flags after the change. Compare bit by bit with OldUacValue.
ValueMeaning
0x1Account disabled.
0x4Password not required.
0x10Normal user account.
0x200Password never expires.
0x800Encrypted text (reversible) password allowed.
0x1000Smart card required.
0x2000Trusted for delegation (unconstrained Kerberos delegation).
0x4000Not delegated (account is sensitive and cannot be delegated).
0x8000Use DES key only.
0x10000Kerberos pre-authentication not required (AS-REP roastable).
0x40000Trusted to authenticate for delegation (protocol transition).
UserAccountControlOne message code per flag that was switched on or off, rendered by Event Viewer as text such as "'Don't Require Preauth' - Enabled". Codes seen in Microsoft's examples include %%2080 (Account Disabled), %%2082 (Password Not Required), %%2084 (Normal Account), %%2087 (Workstation Trust Account) and %%2093 (Trusted For Delegation), each marking the flag as enabled.

Common benign sources

  • Password changes and resets, each producing a 4738 with a new PasswordLastSet.
  • Helpdesk and HR systems updating display names, UPNs, home directories or expiration dates.
  • Accounts being enabled or disabled, which shows up as an Account Disabled flag change.

What attackers do that produces it

  • Disabling Kerberos pre-authentication on a user (flag 0x10000) to AS-REP roast it offline.
  • Setting Password Never Expires or Password Not Required on a backdoor account.
  • Enabling unconstrained or constrained delegation (Trusted For Delegation, AllowedToDelegateTo) on an account the attacker controls.
  • Adding SID history of a privileged account, or a logon script that runs attacker code at logon.

Investigation tips

  • Decode OldUacValue and NewUacValue and alert on weakening flags (0x4, 0x200, 0x800, 0x2000, 0x10000, 0x40000) being turned on.
  • Check the subject — changes to privileged accounts by non-admin or unusual accounts are high priority.
  • On domain controllers, pull 5136 for the same object and time to see the exact attributes and old values.
  • For pre-authentication or delegation changes, look for follow-up Kerberos activity for the account (4768, 4769).

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1558.004 Steal or Forge Kerberos Tickets: AS-REP RoastingCredential Access
T1134.005 Access Token Manipulation: SID-History InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

3 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 2
  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading