Skip to content
Security

Event ID 4741: Computer account created

A computer account was createdSecurity event 4741 is logged on a domain controller when a computer account is created in Active Directory, e.g. by a domain join or a manual pre-creation.
4741
Event ID
4741
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Needs configuration

What event 4741 means

Event 4741 is written on the domain controller that processed the request when a new computer object is created. Subject* identifies who created it and Target* the new account (name ending in $). The event also snapshots initial attributes: SamAccountName, DnsHostName, ServicePrincipalNames, PrimaryGroupId, AllowedToDelegateTo, SidHistory and the SAM account flags.

By default any authenticated domain user can create up to 10 computer accounts (the ms-DS-MachineAccountQuota attribute of the domain). Attackers use that quota to obtain an account they fully control, which is the first step of several attacks: resource-based constrained delegation abuse, the noPac sAMAccountName spoofing chain, and relay attacks that need a machine account. A computer account created by a regular user rather than by an administrator or deployment service is therefore worth a look.

A normal workstation or server join shows PrimaryGroupId 515 (Domain Computers) and NewUacValue 0x80 (workstation trust account), and is followed by a 4742 when the machine updates its DNS name and SPNs.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Computer Account Management (Success).

Only generated on domain controllers. This subcategory is not part of the Windows default audit policy table published by Microsoft, although many domain controller baselines (Microsoft security baselines, CIS) enable it; confirm with auditpol /get /subcategory:"Computer Account Management".

Key fields

FieldWhat it tells you
SubjectUserNameAccount that created the computer object. A standard user here usually means the machine account quota was used.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624 to find the source host.
TargetUserNameName of the new computer account, ending in $.
TargetSidSID of the new computer account.
SamAccountNamePre-Windows 2000 name of the computer account.
DnsHostNameDNS name registered for the computer, if set at creation.
ServicePrincipalNamesSPNs registered for the account, e.g. HOST/ and RestrictedKrbHost/ entries.
PrimaryGroupIdPrimary group RID.
ValueMeaning
515Domain Computers — workstations and member servers.
516Domain Controllers.
521Read-only Domain Controllers.
NewUacValueSAM account flags of the new account (SAM definition, not the AD userAccountControl bits).
ValueMeaning
0x80Workstation trust account — a normal workstation or member server.
0x100Server trust account — a domain controller.
0x2000Trusted for delegation (unconstrained Kerberos delegation).
UserAccountControlThe same flags as message codes, e.g. %%2087 (Workstation Trust Account) for a normal join.
AllowedToDelegateToSPNs for constrained delegation; normally - at creation.
SidHistoryPrevious SIDs; should be - for a new computer account.

Common benign sources

  • Workstations and servers joining the domain, performed by admins, deployment accounts (MDT, SCCM, Autopilot hybrid join) or delegated joiners.
  • Cluster, failover and other roles creating virtual computer objects.

What attackers do that produces it

  • A regular user adding a computer account through the machine account quota (for example with PowerMad or Impacket addcomputer) to prepare RBCD abuse or relay attacks.
  • Creating a computer account as the starting point of noPac, followed by a rename (4781) to a domain controller's name.

Investigation tips

  • Flag computer accounts created by accounts that are not in the approved domain-join or deployment list.
  • Look for a 4742 and 5136 on the same or another computer object shortly after, especially changes to delegation settings.
  • Check whether the new account authenticates (4768, 4769) from hosts that are not the named computer.

MITRE ATT&CK techniques

TechniqueTactics
T1136.002 Create Account: Domain AccountPersistence
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Low · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading