Skip to main content
4732SecurityAccount ManagementSecurity tier 1

Event ID 4732: A member was added to a security-enabled local group

Event ID 4732 is the Windows Security event logged when a member is added to a security-enabled local group, including the built-in Administrators group and domain-local groups on a domain controller. It records who made the change (Subject), which principal was added (Member SID) and which group received it, making it a primary privilege escalation signal.

What Triggers Event 4732

Event ID 4732 comes from the Audit Security Group Management subcategory and fires every time a new member lands in a security-enabled local group. Microsoft's documentation states that it generates on domain controllers, member servers and workstations, and that every added member produces its own 4732. Add three users to a group in one PowerShell call and you get three events, each carrying one Member SID.

The phrase "security-enabled local group" trips people up. It does not mean "a group on a workstation". In Active Directory terms it means a group with the Security type (not Distribution) and Domain local scope. On a domain controller that covers plenty of high-value objects: the built-in Administrators group in the Builtin container, Account Operators, Server Operators, Backup Operators, Print Operators, Remote Desktop Users, and any domain-local group your team created to delegate rights on file shares or GPOs. The sample XML on Microsoft's own page is exactly that case: DC01.contoso.local logging a user being added to AccountOperators.

On a member server or workstation the same event covers the SAM-managed local groups, above all BUILTIN\Administrators. So one event ID spans two very different scopes, and the Group Domain field is how you tell them apart: it reads Builtin for a built-in group, the computer name for a machine-local group, and the domain name for a domain-local group defined in AD.

Two smaller behaviours are worth knowing before you build a rule. First, Microsoft notes you will typically see a 4735 (security-enabled local group was changed) with no visible changes immediately before the 4732; that is normal and not a second modification. Second, 4732 does not fire when a member is removed. The removal counterpart is 4733, so a group that was quietly emptied and refilled produces a pair, not a single event.

Event 4732 Fields

FieldWhat it tells youSimulated value
SubjectUserSidSecurity ID of the account that requested the add-member operation. In this event the Subject is the actor, not a system process.S-1-5-21-424242-127715
SubjectUserNameAccount Name of the account that requested the add-member operation.svc.inventory
SubjectDomainNameAccount Domain of the Subject: domain NetBIOS or DNS name, the computer name for local accounts, or NT AUTHORITY for well-known principals.corp.socsimulator.example
SubjectLogonIdLogon ID, a hexadecimal session value that correlates this change to the Subject's 4624 logon event.simulated-subjectlogonid-29E438
MemberSidMember Security ID: the SID of the account that was added to the group. The only reliable identifier of the new member.simulated-membersid-D67BBB
MemberNameMember Account Name: distinguished name of the added account. For local groups this field typically contains a dash, even when the member is a domain account.simulated-membername-B496FC
TargetSidGroup Security ID: the SID of the group that received the new member. Built-in groups sit under S-1-5-32.S-1-5-21-424242-310532
TargetUserNameGroup Name of the group that received the new member, for example Administrators or ServiceDesk.svc.inventory
TargetDomainNameGroup Domain: domain or computer name of the group; reads Builtin for built-in groups.corp.socsimulator.example
PrivilegeListPrivileges used during the operation, for example SeBackupPrivilege. Often not captured and shown as a dash.simulated-privilegelist-D0BF0B

Inspect Event 4732 Values

Click a field to inspect the full simulated value, the way you would expand it in a SIEM event view.

Example Event 4732 Log

A representative Security entry for Event 4732, generated deterministically by our telemetry engine so every field holds a realistic, internally consistent value.

Simulated example generated by SOCSimulator Research
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-Security-Auditing" />
    <EventID>4732</EventID>
    <Version>0</Version>
    <Level>0</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8020000000000000</Keywords>
    <TimeCreated SystemTime="2025-01-16T05:52:55.000Z" />
    <EventRecordID>143698</EventRecordID>
    <Channel>Security</Channel>
    <Computer>WS-SIM-001.corp.socsimulator.example</Computer>
    <Security />
  </System>
  <EventData>
    <Data Name="SubjectUserSid">S-1-5-21-424242-127715</Data>
    <Data Name="SubjectUserName">svc.inventory</Data>
    <Data Name="SubjectDomainName">corp.socsimulator.example</Data>
    <Data Name="SubjectLogonId">simulated-subjectlogonid-29E438</Data>
    <Data Name="MemberSid">simulated-membersid-D67BBB</Data>
    <Data Name="MemberName">simulated-membername-B496FC</Data>
    <Data Name="TargetSid">S-1-5-21-424242-310532</Data>
    <Data Name="TargetUserName">svc.inventory</Data>
    <Data Name="TargetDomainName">corp.socsimulator.example</Data>
    <Data Name="PrivilegeList">simulated-privilegelist-D0BF0B</Data>
  </EventData>
</Event>

Detecting Event 4732

Member added to the local Administrators group (S-1-5-32-544)

Key on TargetSid, not the group name: Administrators is localised and renameable, the SID is neither.

index=wineventlog EventCode=4732 Group_Security_ID="S-1-5-32-544"
| table _time, host, Account_Name, Account_Domain, Logon_ID, Member_Security_ID, Member_Name, Group_Name, Group_Domain

Account created (4720) and added to a privileged group within 10 minutes

Lucene is the base filter; sequence 4720 to 4732/4728 on the SID in your SIEM. The join key is the 4720 TargetSid matched against the 4732 MemberSid.

index=wineventlog (EventCode=4720 OR EventCode=4732 OR EventCode=4728)
| eval member_sid=if(EventCode=4720, Group_Security_ID, Member_Security_ID)
| transaction member_sid maxspan=10m startswith=(EventCode=4720) endswith=(EventCode=4732 OR EventCode=4728)
| search Group_Security_ID IN ("S-1-5-32-544","S-1-5-32-555","S-1-5-32-551") OR Group_Security_ID="*-512"
| table _time, duration, host, member_sid, Account_Name, Group_Name, Group_Security_ID

Group addition performed by a Subject outside the approved admin list

Allowlist by Subject SID rather than username so a renamed or lookalike account cannot slip through. Keep S-1-5-18 (SYSTEM) in the list only if you separately watch installer windows.

index=wineventlog EventCode=4732
| search NOT [| inputlookup approved_group_admins.csv | fields Security_ID]
| stats count as additions values(Group_Name) as groups values(Member_Security_ID) as members min(_time) as first_seen by Account_Name, Account_Domain, Security_ID, host
| sort - additions

Any membership change on Tier-0 or frozen-membership servers

Domain controllers, ADFS, PKI, backup and hypervisor hosts should see zero 4732 events outside a change record. Alert on presence, not on pattern.

index=wineventlog EventCode=4732
| search [| inputlookup frozen_membership_hosts.csv | fields host]
| table _time, host, Account_Name, Logon_ID, Group_Name, Group_Security_ID, Group_Domain, Member_Security_ID

Group membership added outside change-window hours or at weekends

Adjust the 07:00 to 19:00 window and weekend days to your change policy. In Lucene the @timestamp range uses date math relative to the search day, so run it as a scheduled daily search.

index=wineventlog EventCode=4732
| eval hour=tonumber(strftime(_time,"%H")), dow=strftime(_time,"%a")
| where hour<7 OR hour>=19 OR dow="Sat" OR dow="Sun"
| table _time, host, Account_Name, Account_Domain, Group_Name, Group_Security_ID, Member_Security_ID

Subject: this time the actor really is your suspect

Most Windows audit events name a Subject that turns out to be SYSTEM or the machine account, and analysts learn to ignore it. 4732 is different. Subject Security ID, Account Name, Account Domain and Logon ID describe the account that requested the "add member to the group" operation, and unless the addition was made by an installer running as SYSTEM, that account is a person or a service credential someone controls.

Subject Logon ID is the field to keep. It is the same hexadecimal session identifier stamped on that account's 4624 logon, so pivoting on it gives you the logon type (interactive, RDP, network), the source workstation and the timestamp of the session that performed the change. If the Subject is a domain admin credential and the 4624 shows Logon Type 10 from an unmanaged IP at 02:00, you have your story before you read anything else.

Subject Account Domain tells you whether the operator was a domain principal, a local account on the box, or NT AUTHORITY. An addition to a server's Administrators group performed by a local account rather than a domain admin is unusual in a managed environment and deserves a question of its own.

MITRE ATT&CK® Techniques

Event 4732 telemetry feeds detections for these ATT&CK® techniques:

Practice Investigating Event 4732

Reading about a member was added to a security-enabled local group is one thing. Working the detection inside a live console is another. These free SOCSimulator operations cover the attack techniques Event 4732 helps you detect:

Account Takeover: Impossible-Travel Sign-In

Account Takeover: Impossible-Travel Sign-In

A finance analyst's Microsoft Entra account is accessed without MFA from Moldova 18 minutes after their normal London sign-in. Impossible travel confirmed. The unauthorized session reads the inbox via Graph and adds an external recovery address. Work the Entra audit trail to identify the attacker IP, the compromised mailbox, and the persistence mechanism.

25m·256 tasks
View Operation
Credential Harvesting: The Lookalike Login

Credential Harvesting: The Lookalike Login

Investigate an adversary-in-the-middle (AiTM) credential phishing campaign that lured an employee to a lookalike Microsoft 365 login page. Working entirely from SIEM logs, you will identify the lookalike domain, reconstruct the multi-hop redirect chain through a compromised legitimate site, uncover a secondary phishing wave against another employee, and confirm account takeover in Azure AD sign-in logs via impossible travel and session-token replay. You finish by choosing the containment action that actually evicts an attacker holding a valid session token. Foundational skills for SOC analysts in lookalike-domain analysis and identity-centric incident response.

20m·257 tasks
View Operation
The Template That Read the Disk

The Template That Read the Disk

The file-transfer portal that Tideglow Logistics' partners upload to spent a morning returning host files it was never meant to publish, and finished it running an administrator session nobody had logged into. The root cause is CVE-2024-4040 in CrushFTP 10.6.0. Walk the access logs and firewall traffic step by step to trace how a client holding no credentials turned a request parameter into a read of the host, and that read into a takeover.

25m·256 tasks
View Operation
Start investigating free

Frequently Asked Questions

What does Event ID 4732 mean?
A member was added to a security-enabled local group. That covers machine-local groups such as BUILTIN\Administrators on any Windows host and domain-local security groups on a domain controller. One event is written per member added, on the machine that holds the group.
What is the difference between event 4732 and 4728?
Scope of the group. 4732 fires for security-enabled local groups (local Administrators, domain-local groups). 4728 fires for security-enabled global groups, which is where Domain Admins lives. 4756 covers universal groups. The fields are laid out identically, so one rule can watch all three and rank severity by the group SID.
Why is the Member Account Name blank or "-" in event 4732?
Microsoft documents that for local groups the Member Account Name typically contains "-", even when the added member is a domain account. Only the Member Security ID is reliable. Resolve the SID against Active Directory or the host's SAM, either at ingest or in the query, before you decide who was added.
How do I find who added a user to the local Administrators group?
Filter 4732 on TargetSid S-1-5-32-544 and read the Subject fields: Subject Account Name is the account that made the change and Subject Logon ID links to its 4624 logon, which gives you the logon type and source address. The Member Security ID tells you who was added.
Does event 4732 fire on domain controllers?
Yes. Microsoft states it generates on domain controllers, member servers and workstations. On a DC it records additions to domain-local security groups, including built-in groups such as Administrators, Account Operators, Server Operators and Backup Operators, which are some of the highest-value targets in the forest.

Sources

“Official description, subcategory (Audit Security Group Management), generation scope (DCs, member servers, workstations), one event per member, the 4735 pre-event, the field descriptions including the Member Account Name dash behaviour for local groups, and Microsoft's security monitoring recommendations.”

“T1098 (Account Manipulation) is the ATT&CK technique covering the modification of group membership to maintain or elevate access; the 4732 detection guidance maps to it.”

“Well-known SID reference for the BUILTIN groups under S-1-5-32 (Administrators 544, Power Users 547, Account Operators 548, Server Operators 549, Backup Operators 551, Remote Desktop Users 555, Distributed COM Users 562, Remote Management Users 580) used in the group reference table.”

“Current #1 SERP result; used to establish the coverage gaps listed in information_gain (no queries, no correlation, no SID capability table).”

Event ID

Event ID 4624: Successful Logon, Codes & Queries

Event ID 4624 logs every successful Windows logon. SOCSimulator breaks down the logon type codes, TP/FP triage, and SPL/…

Read more
Event ID

Event ID 4648: Explicit Credentials & How to Detect It

Event ID 4648 logs explicit-credential logons like runas and scheduled tasks. SOCSimulator breaks down the fields and de…

Read more
Event ID

Event ID 4672: Special Logon Privileges, Codes & Queries

Event ID 4672 fields, the 13 sensitive privileges, TP/FP triage, and SPL/KQL/Lucene detection queries for SOC analysts, …

Read more
Glossary

What is Persistence? SOC Glossary

Persistence is the set of techniques an adversary uses to keep access to a compromised system after whatever gave them t…

Read more
Glossary

What is Least Privilege? SOC Glossary

The principle of least privilege states that users, processes, and systems should hold only the minimum access rights re…

Read more
Glossary

What is SIEM? SOC Glossary

Security Information and Event Management (SIEM) is a platform that aggregates, normalizes, and correlates log data from…

Read more
Career Path

SOC Analyst (Tier 1) Career Guide: Salary & Skills

Tier 1 SOC Analysts are the front line. You monitor alert queues, triage incoming detections, classify them as true or f…

Read more
Career Path

Incident Responder Career Guide: Salary & Skills

Incident Responders lead the technical response when confirmed breaches happen. You coordinate containment, run forensic…

Read more
Technique

Account Manipulation (T1098): Detection Training

Account Manipulation keeps an already-compromised account usable by changing its properties rather than creating a new o…

Read more
Technique

Valid Accounts (T1078): Detection Training

Valid Accounts is among the hardest abuses to spot because nothing is technically broken, the adversary simply authentic…

Read more
Comparison

SOCSimulator vs. LetsDefend: Platform Comparison

SOCSimulator wins on operational realism. You get multi-tool shift simulation with SLA pressure, noise injection, and al…

Read more
Event ID

Windows Event ID Library: SOC Reference

Windows Security and Sysmon event IDs with simulated log samples, field tables, and tested detection queries.

Read more