← Event ID reference
4756

A member was added to a security-enabled universal group

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Account changes
  • Warning

What it means

Someone was added to a universal group, which includes Enterprise Admins and Schema Admins.

Why it matters

Changes to forest-wide admin groups are rare and high-impact.

What to do

  • Treat unexpected changes as an incident until explained.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4756
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us