Skip to content
Security

Event ID 4756: Member added to universal group

A member was added to a security-enabled universal groupSecurity event 4756 is logged on a domain controller when a member is added to a security-enabled universal group, such as Enterprise Admins or Schema Admins.
4756
Event ID
4756
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4756 means

Event 4756 is written on the domain controller that processed the change when an account or group is added to a security-enabled universal group. Universal groups can contain members from any domain of the forest and are used for forest-wide roles — most importantly Enterprise Admins and Schema Admins in the forest root domain. Global groups use 4728, local and domain local groups 4732.

The fields are the same as 4728 and 4732: TargetUserName/TargetSid identify the group, MemberName (distinguished name) and MemberSid the new member, Subject* who made the change. One event is logged per added member, usually next to an empty 4755.

An addition to Enterprise Admins gives administrative control over every domain in the forest. Alert on it by SID and treat every occurrence outside a planned change as an incident.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers. Enterprise Admins and Schema Admins live in the forest root domain, so those additions are logged on the root domain's DCs.

Key fields

FieldWhat it tells you
MemberNameDistinguished name of the added member.
MemberSidSID of the added member. The domain part shows which domain of the forest it comes from.
TargetUserNameName of the universal group.
TargetDomainNameDomain of the group.
TargetSidSID of the group; identify well-known groups by their RID.
ValueMeaning
*-518Schema Admins (forest root domain).
*-519Enterprise Admins (forest root domain).
SubjectUserNameAccount that added the member.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Administrators maintaining universal groups used for Exchange, messaging or cross-domain resource access.
  • Temporary Schema Admins membership for an approved schema extension, removed afterward (4757).

What attackers do that produces it

  • Adding a controlled account to Enterprise Admins after compromising a domain to gain control of the whole forest.
  • Adding accounts to universal groups that hold delegated rights across domains.

Investigation tips

  • Alert on any change to Enterprise Admins and Schema Admins and confirm it with the forest owners.
  • Check the member's origin (MemberSid domain part), creation date (4720) and subsequent logons (4624, 4672).
  • Pivot on SubjectLogonId to find the source host of the change.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading