Skip to content
Security

Event ID 4780: AdminSDHolder ACL applied

The ACL was set on accounts which are members of administrators groupsSecurity event 4780 is logged when SDProp resets the ACL of a protected admin account to match AdminSDHolder, revealing ACL changes on privileged accounts.
4780
Event ID
4780
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4780 means

Event 4780 comes from the SDProp process. Every hour, the domain controller holding the PDC emulator role compares the ACL of every protected account and group (members of administrative groups, marked with adminCount = 1) with the ACL of the AdminSDHolder object. When they differ, it overwrites the object's ACL with the AdminSDHolder template and logs 4780 for that object.

In other words, a 4780 means that the ACL of a privileged account had been changed since the last SDProp run — by a delegation tool, an administrator, or an attacker granting themselves rights (reset password, write members) on an admin account. It is also logged when an account newly becomes protected, for example right after being added to a privileged group.

The reverse also matters: if an attacker modifies the ACL of AdminSDHolder itself, SDProp will silently propagate the malicious ACL to every protected account. That change is not reported by 4780; audit it with directory service change events (5136) on the AdminSDHolder object.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.

Only generated on the domain controller holding the PDC emulator role. Microsoft notes that the event is not generated on some OS versions.

Key fields

FieldWhat it tells you
TargetUserNameProtected account or group whose ACL was reset.
TargetDomainNameDomain of the target.
TargetSidSID of the target.
SubjectUserNameSecurity context in which SDProp applied the ACL.
SubjectLogonIdLogon session of the subject.
PrivilegeListPrivileges used for the operation, often -.

Common benign sources

  • An account just added to a protected group (Domain Admins, Account Operators and so on) receives the AdminSDHolder ACL at the next SDProp run.
  • Administrative tools that modify permissions on admin accounts, which SDProp then reverts.

What attackers do that produces it

  • An attacker granting themselves rights on an administrator account (for example a delegated password reset) — SDProp reverts it and logs 4780 for that account.
  • Newly protected accounts appearing after an attacker adds them to privileged groups.

Investigation tips

  • For each target, look for group membership changes (4728, 4732, 4756) or ACL changes (5136) in the preceding hour.
  • Recurring 4780 for the same account means something keeps changing its ACL; find the source.
  • Separately monitor 5136 on the AdminSDHolder object, which this event does not cover.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading