Event ID 4742: Computer account changed
- Event ID
- 4742
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Needs configuration
What event 4742 means
Event 4742 is written on the domain controller that processed the change each time a computer object is modified, one event per change. Subject* identifies who made the change and Target* the computer account. Attributes that did not change are shown as -; a change to an attribute outside the event's list (for example the Description or the object's ACL) produces a 4742 in which everything is -.
Most 4742 events are routine: computers rotate their machine account password every 30 days by default (PasswordLastSet), and a newly joined machine updates its own DnsHostName and ServicePrincipalNames after rebooting — in that case the subject and target are the same computer account.
The interesting cases involve delegation and flags: UserAccountControl showing Trusted For Delegation (%%2093) enabled, a new AllowedToDelegateTo list, or a DC-only flag appearing on a regular computer. Resource-based constrained delegation is configured through the msDS-AllowedToActOnBehalfOfOtherIdentity attribute, which is not listed in 4742 — use 5136 for that.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit Computer Account Management (Success).
Only generated on domain controllers. This subcategory is not part of the Windows default audit policy table published by Microsoft, although many domain controller baselines (Microsoft security baselines, CIS) enable it; confirm with auditpol /get /subcategory:"Computer Account Management". If a user-only flag is set on a computer account, the account becomes a user-type account and later changes are logged as 4738.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that made the change. The computer itself (HOST$) for self-updates after a join or password rotation. |
| SubjectLogonId | Logon session of the subject on the DC; correlate with 4624. |
| TargetUserName | Computer account that was changed. |
| TargetSid | SID of the changed computer account. |
| SamAccountName | New account name if it changed (also logged as 4781). |
| PasswordLastSet | New machine password timestamp. Changes much more frequent than the rotation interval are unusual. |
| DnsHostName | New DNS host name if it changed. |
| ServicePrincipalNames | Complete new SPN list if it changed (the full list, not the difference). |
| AllowedToDelegateTo | New list of SPNs for constrained delegation, or <value not set> if cleared. |
| PrimaryGroupId | New primary group RID; 515 for member computers, 516 for DCs, 521 for RODCs. |
| OldUacValue | SAM account flags before the change. |
| NewUacValue | SAM account flags after the change, e.g. 0x80 to 0x2080 when unconstrained delegation is enabled on a workstation account. |
| UserAccountControl | Flags switched on or off, as message codes such as %%2093 (Trusted For Delegation enabled). |
Common benign sources
- Machine account password rotation (every 30 days by default).
- Newly joined computers updating their DNS host name and SPNs after the first reboot.
- Administrators configuring constrained delegation for application servers.
What attackers do that produces it
- Enabling unconstrained delegation on a computer the attacker controls to capture forwarded TGTs.
- Adding or changing SPNs and delegation targets on a computer account under attacker control.
- Renaming a computer account as part of noPac (with 4781).
Investigation tips
- Filter out self-changes (subject equals target) and routine password rotation, then review the rest.
- Alert on Trusted For Delegation or AllowedToDelegateTo changes on any computer that is not a DC.
- Pull 5136 events for the same object to see attributes not covered by 4742, such as RBCD settings.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumPossible DC Shadow AttackRule by Ilyas Ochkov, oscd.community, Chakib Gzenayi (@Chak092), Hosni Mribah, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.