Skip to content
Security

Event ID 4739: Domain policy changed

Domain Policy was changedSecurity event 4739 logs a change to domain password, lockout or logoff policy, or to ms-DS-MachineAccountQuota. Only the changed values are filled in.
4739
Event ID
4739
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Policy changes
Default logging
Logged by default

What event 4739 means

Event 4739 is written when the domain account policy changes: password policy (length, age, history, complexity), account lockout policy, the force-logoff setting, or domain attributes such as ms-DS-MachineAccountQuota and the domain behavior version. DomainPolicyChanged says which policy area changed, and each attribute field shows the new value — unchanged attributes are -.

Weakening these settings helps attackers: lowering the lockout threshold to zero enables unlimited password guessing, reducing complexity or length eases spraying, and enabling reversible encryption (PasswordProperties 16 or 17) stores recoverable passwords for accounts that change their password afterwards.

Changes normally come from editing the Default Domain Policy GPO, so the subject is often the DC computer account. Find the human editor through directory change events on the GPO.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Policy Change > Audit Authentication Policy Change (Success). Enabled for Success in the default Windows audit policy.

Domain policy changes are recorded on domain controllers.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that applied the change, often the DC computer account (DC01$).
SubjectLogonIdLogon session of the subject; 0x3e7 for SYSTEM.
DomainPolicyChangedPolicy area changed — Password Policy, Lockout Policy, Logoff Policy, or - for a change to Machine Account Quota.
DomainNameNetBIOS name of the domain.
DomainSidSID of the domain.
MinPasswordLengthNew minimum password length, or - if unchanged.
PasswordHistoryLengthNew number of remembered passwords, or -.
MaxPasswordAgeNew maximum password age, or -.
PasswordPropertiesPassword complexity and reversible encryption settings, or - if unchanged.
ValueMeaning
0Complexity disabled, reversible encryption disabled.
1Complexity enabled, reversible encryption disabled.
16Complexity disabled, reversible encryption enabled.
17Complexity enabled, reversible encryption enabled.
LockoutThresholdNew number of failed attempts before lockout; 0 means accounts never lock out.
LockoutDurationNew lockout duration, or -.
LockoutObservationWindowNew "reset account lockout counter after" window, or -.
MachineAccountQuotaNew value of ms-DS-MachineAccountQuota — how many computer accounts a regular user may join (default 10).
DomainBehaviorVersionNew domain functional level (msDS-Behavior-Version), or -.

Common benign sources

  • Planned password or lockout policy updates in the Default Domain Policy.
  • Setting ms-DS-MachineAccountQuota to 0 as a hardening step.
  • Raising the domain functional level during a DC upgrade project.

What attackers do that produces it

  • Setting LockoutThreshold to 0 or shortening the lockout window before password spraying.
  • Enabling reversible encryption or lowering length and complexity requirements.
  • Raising ms-DS-MachineAccountQuota so a low-privileged user can create computer accounts, a prerequisite for several relay and delegation attacks.

Investigation tips

  • Read only the fields that are not -; those are the attributes that changed.
  • Compare the new values to the documented baseline and flag any weakening.
  • Find the GPO or domain object edit with 5136 to identify the account that made it.

MITRE ATT&CK techniques

TechniqueTactics
T1484 Domain or Tenant Policy ModificationDefense Impairment, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading