Event ID 4780: AdminSDHolder ACL applied
- Event ID
- 4780
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- User accounts
- Default logging
- Logged by default
What event 4780 means
Event 4780 comes from the SDProp process. Every hour, the domain controller holding the PDC emulator role compares the ACL of every protected account and group (members of administrative groups, marked with adminCount = 1) with the ACL of the AdminSDHolder object. When they differ, it overwrites the object's ACL with the AdminSDHolder template and logs 4780 for that object.
In other words, a 4780 means that the ACL of a privileged account had been changed since the last SDProp run — by a delegation tool, an administrator, or an attacker granting themselves rights (reset password, write members) on an admin account. It is also logged when an account newly becomes protected, for example right after being added to a privileged group.
The reverse also matters: if an attacker modifies the ACL of AdminSDHolder itself, SDProp will silently propagate the malicious ACL to every protected account. That change is not reported by 4780; audit it with directory service change events (5136) on the AdminSDHolder object.
When it is logged
Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success). Enabled for Success in the default Windows audit policy.
Only generated on the domain controller holding the PDC emulator role. Microsoft notes that the event is not generated on some OS versions.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Protected account or group whose ACL was reset. |
| TargetDomainName | Domain of the target. |
| TargetSid | SID of the target. |
| SubjectUserName | Security context in which SDProp applied the ACL. |
| SubjectLogonId | Logon session of the subject. |
| PrivilegeList | Privileges used for the operation, often -. |
Common benign sources
- An account just added to a protected group (Domain Admins, Account Operators and so on) receives the AdminSDHolder ACL at the next SDProp run.
- Administrative tools that modify permissions on admin accounts, which SDProp then reverts.
What attackers do that produces it
- An attacker granting themselves rights on an administrator account (for example a delegated password reset) — SDProp reverts it and logs 4780 for that account.
- Newly protected accounts appearing after an attacker adds them to privileged groups.
Investigation tips
- For each target, look for group membership changes (4728, 4732, 4756) or ACL changes (5136) in the preceding hour.
- Recurring 4780 for the same account means something keeps changing its ACL; find the source.
- Separately monitor 5136 on the AdminSDHolder object, which this event does not cover.
MITRE ATT&CK techniques
| Technique | Tactics |
|---|---|
| T1098 Account Manipulation | Persistence, Privilege Escalation |
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.