Event ID: 4728

A member was added to a security-enabled global group

A member was added to a security-enabled global group.

    Security ID:        %6
    Account Name:       %7
    Account Domain:     %8
    Logon ID:           %9

    Security ID:        %2
    Account Name:       %1

    Security ID:        %5
    Group Name:         %3
    Group Domain:       %4

Additional Information:
    Privileges:         %10

Auditing:     Always

Since security groups may control access to sensitive data & settings, changes to security group memberships should always be audited.

Volume:     Low

ISO 27001:2013 A9.2.5
NIST 800-171: 3.1.1
NIST SP 800-53: AC-2 (4)

Name Field Insertion String OS Example
Account Name MemberName %1 Any -
Security ID MemberSid %2 Any S-1-5-21-345695894-305466303-1622526952-1000
Group Name TargetUserName %3 Any None
Group Domain TargetDomainName %4 Any ComputerName
Security ID TargetSid %5 Any S-1-5-21-345695894-305466303-1622526952-513
Security ID SubjectUserSid %6 Any S-1-5-18
Account Name SubjectUserName %7 Any ComputerName$
Account Domain SubjectDomainName %8 Any WORKGROUP
Logon ID SubjectLogonId %9 Any 0x3e7
Privileges PrivilegeList %10 Any View Codes

Lookup Audit Policy Configuration Settings

C:\> AuditPol.exe /get /subcategory:"Security Group Management"

LEFT/RIGHT arrow keys for navigation

Back to List