4730 Security log · Account Management high severity low volume

Windows Event ID 4730 — A security-enabled global group was deleted

A global security group was deleted.

Why event 4730 matters

Deletion of security groups disrupts access controls and can blind monitoring (deleting groups used in SACL). Sabotage of AD structure.

How to detect it

Alert: deletion of groups used for security, admin, or IT functions. Alert: outside business hours.

Log source
Security
Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).
Fields to pivot on
SubjectUserNameTargetUserNameLogonTypeIpAddressWorkstationName

MITRE ATT&CK mapping

Tactic Technique
Impact Account Access Removal (T1531)

Detection queries

Starting points — adapt the log source, projected fields and thresholds for your environment.

Sentinel / Defender KQL
SecurityEvent
| where EventID == 4730   // A security-enabled global group was deleted
| project TimeGenerated, Computer, SubjectUserName, TargetUserName, LogonType, IpAddress, WorkstationName
| sort by TimeGenerated desc
Splunk SPL
index=* sourcetype="WinEventLog:Security" EventCode=4730
| stats count earliest(_time) as first_seen latest(_time) as last_seen by ComputerName
| sort - count   `# A security-enabled global group was deleted — add EventData fields: SubjectUserName, TargetUserName, LogonType, IpAddress`
Hunt event 4730 in Sentinel/Defender →
Build a KQL query for this event in the KQL Query Builder.
Search all event IDs →
Open the interactive Windows Event ID lookup.

Related Account Management events

4720 A user account was created 4722 A user account was enabled 4723 An attempt was made to change an account's password 4724 An attempt was made to reset an account's password 4725 A user account was disabled 4726 A user account was deleted 4728 A member was added to a security-enabled global group 4729 A member was removed from a security-enabled global group 4731 A security-enabled local group was created 4732 A member was added to a security-enabled local group 4733 A member was removed from a security-enabled local group 4734 A security-enabled local group was deleted

Frequently asked questions

What is Windows Event ID 4730?

A security-enabled global group was deleted. A global security group was deleted.

Which log records event 4730?

Event 4730 is written to the Security channel by Microsoft-Windows-Security-Auditing. Advanced Audit Policy — enable the 'Account Management' subcategory (Success and/or Failure).

What MITRE ATT&CK techniques map to event 4730?

Event 4730 is associated with: Account Access Removal (T1531).

How do you detect activity around event 4730?

Alert: deletion of groups used for security, admin, or IT functions. Alert: outside business hours.