Event ID 4739: Domain policy changed
- Event ID
- 4739
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Policy changes
- Default logging
- Logged by default
What event 4739 means
Event 4739 is written when the domain account policy changes: password policy (length, age, history, complexity), account lockout policy, the force-logoff setting, or domain attributes such as ms-DS-MachineAccountQuota and the domain behavior version. DomainPolicyChanged says which policy area changed, and each attribute field shows the new value — unchanged attributes are -.
Weakening these settings helps attackers: lowering the lockout threshold to zero enables unlimited password guessing, reducing complexity or length eases spraying, and enabling reversible encryption (PasswordProperties 16 or 17) stores recoverable passwords for accounts that change their password afterwards.
Changes normally come from editing the Default Domain Policy GPO, so the subject is often the DC computer account. Find the human editor through directory change events on the GPO.
When it is logged
Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.
Domain policy changes are recorded on domain controllers.
Key fields
| Field | What it tells you | ||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that applied the change, often the DC computer account (DC01$). | ||||||||||
| SubjectLogonId | Logon session of the subject; 0x3e7 for SYSTEM. | ||||||||||
| DomainPolicyChanged | Policy area changed — Password Policy, Lockout Policy, Logoff Policy, or - for a change to Machine Account Quota. | ||||||||||
| DomainName | NetBIOS name of the domain. | ||||||||||
| DomainSid | SID of the domain. | ||||||||||
| MinPasswordLength | New minimum password length, or - if unchanged. | ||||||||||
| PasswordHistoryLength | New number of remembered passwords, or -. | ||||||||||
| MaxPasswordAge | New maximum password age, or -. | ||||||||||
| PasswordProperties | Password complexity and reversible encryption settings, or - if unchanged.
| ||||||||||
| LockoutThreshold | New number of failed attempts before lockout; 0 means accounts never lock out. | ||||||||||
| LockoutDuration | New lockout duration, or -. | ||||||||||
| LockoutObservationWindow | New "reset account lockout counter after" window, or -. | ||||||||||
| MachineAccountQuota | New value of ms-DS-MachineAccountQuota — how many computer accounts a regular user may join (default 10). | ||||||||||
| DomainBehaviorVersion | New domain functional level (msDS-Behavior-Version), or -. |
Common benign sources
- Planned password or lockout policy updates in the Default Domain Policy.
- Setting
ms-DS-MachineAccountQuotato 0 as a hardening step. - Raising the domain functional level during a DC upgrade project.
What attackers do that produces it
- Setting
LockoutThresholdto 0 or shortening the lockout window before password spraying. - Enabling reversible encryption or lowering length and complexity requirements.
- Raising
ms-DS-MachineAccountQuotaso a low-privileged user can create computer accounts, a prerequisite for several relay and delegation attacks.
Investigation tips
- Read only the fields that are not
-; those are the attributes that changed. - Compare the new values to the documented baseline and flag any weakening.
- Find the GPO or domain object edit with 5136 to identify the account that made it.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1484 Domain or Tenant Policy Modification | Defense Impairment, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.