Event ID 4741: Computer account created
- Event ID
- 4741
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Needs configuration
What event 4741 means
Event 4741 is written on the domain controller that processed the request when a new computer object is created. Subject* identifies who created it and Target* the new account (name ending in $). The event also snapshots initial attributes: SamAccountName, DnsHostName, ServicePrincipalNames, PrimaryGroupId, AllowedToDelegateTo, SidHistory and the SAM account flags.
By default any authenticated domain user can create up to 10 computer accounts (the ms-DS-MachineAccountQuota attribute of the domain). Attackers use that quota to obtain an account they fully control, which is the first step of several attacks: resource-based constrained delegation abuse, the noPac sAMAccountName spoofing chain, and relay attacks that need a machine account. A computer account created by a regular user rather than by an administrator or deployment service is therefore worth a look.
A normal workstation or server join shows PrimaryGroupId 515 (Domain Computers) and NewUacValue 0x80 (workstation trust account), and is followed by a 4742 when the machine updates its DNS name and SPNs.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Computer Account Management (Success).
Only generated on domain controllers. This subcategory is not part of the Windows default audit policy table published by Microsoft, although many domain controller baselines (Microsoft security baselines, CIS) enable it; confirm with auditpol /get /subcategory:"Computer Account Management".
Key fields
| Field | What it tells you | ||||||||
|---|---|---|---|---|---|---|---|---|---|
| SubjectUserName | Account that created the computer object. A standard user here usually means the machine account quota was used. | ||||||||
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624 to find the source host. | ||||||||
| TargetUserName | Name of the new computer account, ending in $. | ||||||||
| TargetSid | SID of the new computer account. | ||||||||
| SamAccountName | Pre-Windows 2000 name of the computer account. | ||||||||
| DnsHostName | DNS name registered for the computer, if set at creation. | ||||||||
| ServicePrincipalNames | SPNs registered for the account, e.g. HOST/ and RestrictedKrbHost/ entries. | ||||||||
| PrimaryGroupId | Primary group RID.
| ||||||||
| NewUacValue | SAM account flags of the new account (SAM definition, not the AD userAccountControl bits).
| ||||||||
| UserAccountControl | The same flags as message codes, e.g. %%2087 (Workstation Trust Account) for a normal join. | ||||||||
| AllowedToDelegateTo | SPNs for constrained delegation; normally - at creation. | ||||||||
| SidHistory | Previous SIDs; should be - for a new computer account. |
Common benign sources
- Workstations and servers joining the domain, performed by admins, deployment accounts (MDT, SCCM, Autopilot hybrid join) or delegated joiners.
- Cluster, failover and other roles creating virtual computer objects.
What attackers do that produces it
- A regular user adding a computer account through the machine account quota (for example with PowerMad or Impacket addcomputer) to prepare RBCD abuse or relay attacks.
- Creating a computer account as the starting point of noPac, followed by a rename (4781) to a domain controller's name.
Investigation tips
- Flag computer accounts created by accounts that are not in the approved domain-join or deployment list.
- Look for a 4742 and 5136 on the same or another computer object shortly after, especially changes to delegation settings.
- Check whether the new account authenticates (4768, 4769) from hosts that are not the named computer.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Low · 1
- LowAdd or Remove Computer from DCRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.