Skip to content
Security

Event ID 4757: Member removed from universal group

A member was removed from a security-enabled universal groupSecurity event 4757 is logged on a domain controller when a member is removed from a security-enabled universal group, such as Enterprise Admins.
4757
Event ID
4757
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Groups
Default logging
Logged by default

What event 4757 means

Event 4757 is the counterpart of 4756: it is written on the domain controller that processed the change when a member is removed from a security-enabled universal group. Global groups use 4729, local and domain local groups 4733.

TargetUserName/TargetSid identify the group, MemberName and MemberSid the removed member, Subject* who removed it. One event is logged per removed member, usually next to an empty 4755.

Removals from Schema Admins after a schema update are expected. A removal that closely follows an unexplained 4756 for the same member points to short-lived, possibly malicious, forest-level privilege.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit Security Group Management (Success). Success is audited in the default Windows audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
MemberNameDistinguished name of the removed member.
MemberSidSID of the removed member.
TargetUserNameName of the universal group.
TargetDomainNameDomain of the group.
TargetSidSID of the group; RID 519 is Enterprise Admins, 518 Schema Admins.
SubjectUserNameAccount that removed the member.
SubjectDomainNameDomain of the subject.
SubjectLogonIdLogon session of the subject on the DC; correlate with 4624.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • Removing temporary Schema Admins or Enterprise Admins membership after planned maintenance.
  • Group cleanup and access reviews.

What attackers do that produces it

  • Removing a temporarily added account from Enterprise Admins to hide forest-level access.
  • Removing legitimate administrators from forest-level groups to hinder recovery.

Investigation tips

  • Pair with the preceding 4756 for the same member and review what happened in between.
  • Confirm removals from Enterprise Admins or Schema Admins with the forest owners.

MITRE ATT&CK techniques

TechniqueTactics
T1098.007 Account Manipulation: Additional Local or Domain GroupsPersistence, Privilege Escalation
T1531 Account Access RemovalImpact

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading