Event ID 4766: SID History add failed
- Event ID
- 4766
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Needs configuration
What event 4766 means
Event 4766 is the failure counterpart of 4765: a request to add SIDs to an account's sIDHistory was rejected by the domain controller. It records the subject that made the attempt, the target account and the source account whose SID was supposed to be copied.
During migrations, failures happen because of missing trust settings, auditing prerequisites or permissions, and they come in batches from the migration account. Outside a migration, a failed attempt is a sign that someone is trying SID History injection and may retry with other means.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Failure). Only Success is audited by default, so Failure auditing must be enabled.
Only generated on domain controllers. Microsoft does not publish a sample of this event.
Key fields
| Field | What it tells you |
|---|---|
| SubjectUserName | Account that attempted to add the SID History. |
| SubjectLogonId | Logon session of the subject; correlate with 4624. |
| TargetUserName | Account that was supposed to receive the SID History. |
| TargetDomainName | Domain of the target account. |
| TargetSid | SID of the target account. |
| PrivilegeList | Privileges used for the attempt, often -. |
Common benign sources
- Migration tools failing because a prerequisite (trust, auditing in the source domain, permissions) is missing.
What attackers do that produces it
- Unsuccessful SID History injection attempt against a controlled account.
Investigation tips
- Identify the subject and source host; outside a migration, treat it as an attempted privilege escalation.
- Look for a later successful 4765 or SidHistory changes in 4738 and 5136 for the same target.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1134.005 Access Token Manipulation: SID-History Injection | Stealth, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Medium · 1
- MediumAddition of SID History to Active Directory ObjectRule by Thomas Patzke, @atc_project (improvements), SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.