4723 Security log · Account Management low severity medium volume

Windows Event ID 4723 — An attempt was made to change an account's password

User-initiated password change (not admin reset). SubjectUserName and TargetUserName are typically the same.

Why event 4723 matters

Attacker who has compromised an account may change the password to lock out the legitimate user (T1531). Watch for changes immediately before 4647 (logoff) of that account.

How to detect it

Alert: SubjectUserName != TargetUserName (that is a reset, use 4724). Alert: password change immediately before account disable (4725). Low noise, cross-correlate for context.

Log source
Security
Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Impact Account Access Removal (T1531)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4723   // An attempt was made to change an account's password
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4723
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# An attempt was made to change an account's password — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4723 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Account Management events

4720 A user account was created 4722 A user account was enabled 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4730 A security-enabled global group was deleted 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group 4734 A security-enabled local group was deleted

Frequently asked questions

What is Windows Event ID 4723?

An attempt was made to change an account's password. User-initiated password change (not admin reset). SubjectUserName and TargetUserName are typically the same.

Which log records event 4723?

Event 4723 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4723?

Event 4723 is associated with: Account Access Removal (T1531).

How do you detect activity around event 4723?

Alert: SubjectUserName != TargetUserName (that is a reset, use 4724). Alert: password change immediately before account disable (4725). Low noise, cross-correlate for context.