Skip to content
Security

Event ID 4767: Account unlocked

A user account was unlockedSecurity event 4767 is logged when a locked-out user account is unlocked, recording who unlocked it and which account.
4767
Event ID
4767
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4767 means

Event 4767 is written when a locked-out account is unlocked — on domain controllers for domain accounts and on member servers and workstations for local accounts. Subject* identifies who unlocked the account and Target* the account that was unlocked.

It usually closes a lockout story: 4740 (locked), then 4767 (unlocked by the helpdesk), often with a 4724 password reset. Reading these three events together tells you how long the account was unavailable and who restored access.

Because unlocking re-enables authentication, an unlock by an unexpected account, or right after a burst of failed logons from an unknown source, lets an attacker continue guessing or use a password they have obtained.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that unlocked the target account.
SubjectDomainNameDomain or computer name of the subject.
SubjectLogonIdLogon session of the subject; correlate with 4624.
TargetUserNameAccount that was unlocked.
TargetDomainNameDomain of the unlocked account, or the computer name for a local account.
TargetSidSID of the unlocked account.

Common benign sources

  • Helpdesk unlocking a user after a lockout, often together with a password reset (4724).
  • Self-service password reset tools unlocking accounts on behalf of users.

What attackers do that produces it

  • Unlocking an account locked by password guessing so the attack can continue, or so a compromised password can be used.

Investigation tips

  • Match the unlock with the preceding 4740 for the same TargetSid and review the lockout's caller computer.
  • Verify that SubjectUserName is a helpdesk or self-service account and that the user requested it.
  • Look for a logon by the target (4624) soon after the unlock and check its source.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading