Skip to main content
AD Academy
Back to all events
4728Security (DC)Groups & rightsCRITLast updated:

Member added to a global group (e.g. Domain Admins)

What it means

Someone gained rights through a global group. For Domain Admins / Enterprise Admins this is a top-priority alert.

When it is normal and when it is suspicious

Normal: adding to an ordinary working group per a helpdesk ticket. Always suspicious: adding to Domain Admins — even if 'planned'.

First steps

  1. 1Match it to an approved change — otherwise remove the member now.
  2. 2Check the actor: was he himself recently added to a privileged group?
  3. 3Siblings: 4732 (domain local) and 4756 (universal).

Fields worth checking

FieldWhat to look at
TargetUserName (group)The group name. Your SIEM should have a predefined list of sensitive groups.
MemberSidWho was added — work by SID, names change.
SubjectWho did it. An unfamiliar admin account means investigate now.

Related events

This reference is a starting point for investigation, not a replacement for your organisation's security policy.