Skip to content
Security

Event ID 4794: DSRM password set attempt

An attempt was made to set the Directory Services Restore Mode administrator passwordSecurity event 4794 is logged on a domain controller when someone sets the DSRM administrator password. Rare, and abused for DC persistence.
4794
Event ID
4794
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
User accounts
Default logging
Logged by default

What event 4794 means

Event 4794 is written on a domain controller when an attempt is made to set the Directory Services Restore Mode (DSRM) administrator password — the local administrator account each DC keeps for offline recovery. Status is 0x0 for success; any other value is a failed attempt.

Changing this password is a rare administrative task, usually done with ntdsutil ("set dsrm password", optionally syncing from a domain account). That rarity is what makes it valuable: a known attacker persistence technique sets the DSRM password to a known value and then changes the DsrmAdminLogonBehavior registry value so the DSRM account can log on over the network while the DC runs normally, giving a backdoor local administrator on the DC.

Every 4794 should be traced to a change ticket. Correlate with registry auditing or EDR telemetry for HKLM\System\CurrentControlSet\Control\Lsa\DsrmAdminLogonBehavior.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Account Management > Audit User Account Management (Success, Failure). Success is enabled in the default audit policy.

Only generated on domain controllers.

Key fields

FieldWhat it tells you
SubjectUserNameAccount that attempted to set the DSRM password.
SubjectDomainNameDomain of that account.
SubjectLogonIdLogon session of the account; pivot to 4624 on the DC to see how it logged on.
WorkstationComputer the request came from. Equals the DC's own name when the change was made locally, e.g. with ntdsutil on the console.
StatusResult code; 0x0 means the password was set, anything else is a failure.

Common benign sources

  • Planned DSRM password rotation by domain administrators, typically with ntdsutil.
  • DC promotion and recovery procedures that set the DSRM password.

What attackers do that produces it

  • DSRM backdoor: setting a known DSRM password (sometimes synced from a controlled domain account), then enabling network logon for it via DsrmAdminLogonBehavior.
  • A domain admin session from an unusual workstation changing the DSRM password on several DCs.

Investigation tips

  • Confirm the change was planned; the event should be extremely rare.
  • Check the DC's registry (or registry audit / EDR data) for DsrmAdminLogonBehavior set to 2, which allows network logons with the DSRM account.
  • Pivot on SubjectLogonId to the logon (4624) and look at what else that session did on the DC (4688).
  • Watch for later network logons to the DC with a local account named like the DC's built-in administrator.

MITRE ATT&CK techniques

TechniqueTactics
T1098 Account ManipulationPersistence, Privilege Escalation
T1078.003 Valid Accounts: Local AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading