Skip to content
Security

Event ID 4766: SID History add failed

An attempt to add SID History to an account failedSecurity event 4766 is logged on a domain controller when an attempt to add SID History to an account fails — worth checking outside a migration project.
4766
Event ID
4766
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Needs configuration

What event 4766 means

Event 4766 is the failure counterpart of 4765: a request to add SIDs to an account's sIDHistory was rejected by the domain controller. It records the subject that made the attempt, the target account and the source account whose SID was supposed to be copied.

During migrations, failures happen because of missing trust settings, auditing prerequisites or permissions, and they come in batches from the migration account. Outside a migration, a failed attempt is a sign that someone is trying SID History injection and may retry with other means.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Failure). Only Success is audited by default, so Failure auditing must be enabled.

Only generated on domain controllers. Microsoft does not publish a sample of this event.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that attempted to add the SID History.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount that was supposed to receive the SID History.
TargetDomainNameDomain of the target account.
TargetSidSID of the target account.
PrivilegeListPrivileges used for the attempt, often -.

Common benign sources

  • Migration tools failing because a prerequisite (trust, auditing in the source domain, permissions) is missing.

What attackers do that produces it

  • Unsuccessful SID History injection attempt against a controlled account.

Investigation tips

  • Identify the subject and source host; outside a migration, treat it as an attempted privilege escalation.
  • Look for a later successful 4765 or SidHistory changes in 4738 and 5136 for the same target.

MITRE ATT&CK techniques

TechniqueTactics
T1134.005 Access Token Manipulation: SID-History InjectionStealth, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Medium · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading