Event ID 4742 is a Windows security log event indicating that a computer account was changed. In Zerologon investigations, this event becomes especially important when the change is made by Anonymous Logon, because that pattern can signal suspicious or malicious password reset activity on a domain controller.
Expanded Definition
Event ID 4742 is a Windows Security audit record that indicates a computer account was changed. In Active Directory environments, that “change” can include password updates, attribute modifications, or other directory updates tied to a machine account. For NHI security teams, the event matters because computer accounts are machine identities, and their compromise can create durable access paths across a domain.
In Zerologon investigations, Event ID 4742 becomes especially significant when the change is attributed to Anonymous Logon on a domain controller. That pattern can indicate a failed or abused authentication path that resulted in a computer account password reset or related directory tampering. Definitions vary across vendors on how much weight to give this event in isolation, but the operational view is consistent: it is a high-signal artifact that must be correlated with adjacent authentication, replication, and controller events. The NIST Cybersecurity Framework 2.0 supports this kind of correlation-driven detection and response logic.
The most common misapplication is treating Event ID 4742 as routine account maintenance, which occurs when analysts do not verify the initiating security context and the target system role.
Examples and Use Cases
Implementing detection for Event ID 4742 rigorously often introduces alert noise, requiring organisations to weigh faster compromise detection against the cost of deeper correlation and triage.
- A domain controller logs 4742 immediately after an Anonymous Logon event, prompting an investigation for Zerologon-style abuse and machine account tampering.
- A computer account password change occurs during approved maintenance, and the event is validated against change windows, administrator activity, and directory service logs.
- A blue team correlates 4742 with logon failures, replication anomalies, and account metadata changes to distinguish legitimate admin action from malicious reset activity.
- An incident responder uses the event as a pivot to identify whether a server’s trust relationship may have been altered after unauthorized access.
- A detection engineer tunes rules to focus on 4742 events affecting critical controllers or high-value machine accounts rather than every routine workstation update.
For background on machine identity governance and the scale of identity exposure, see the Ultimate Guide to NHIs. For event semantics and detection context, compare the log signal with guidance in the NIST Cybersecurity Framework 2.0 and your Windows audit policy.
Why It Matters in NHI Security
Event ID 4742 matters because computer accounts are not just infrastructure objects, they are privileged NHIs that can authenticate, replicate, and trust other systems. When a malicious actor resets or alters a domain controller computer account, the impact can extend far beyond a single host into domain-wide authentication integrity. This is why 80% of identity breaches involved compromised non-human identities such as service accounts and API keys, according to NHI Mgmt Group in the Ultimate Guide to NHIs.
Misreading this event can lead to missed indicators of lateral movement, persistence, or trust manipulation. It also creates governance blind spots, especially where machine-account changes are not reviewed with the same rigor as human identity changes. In practice, this event helps security teams answer whether a controller or machine identity has been touched in a way that violates expected administrative flow. The NIST Cybersecurity Framework 2.0 reinforces the need for timely detection, analysis, and response around such identity-related events. Organisations typically encounter the importance of Event ID 4742 only after a domain controller has been abused, at which point it becomes operationally unavoidable to address.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST Zero Trust (SP 800-207) and NIST SP 800-63 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Non-Human Identity Top 10 | NHI-01 | Computer account changes can indicate compromised machine identity lifecycle control. |
| NIST CSF 2.0 | DE.CM-8 | Security monitoring should capture anomalous identity and account-change events. |
| NIST Zero Trust (SP 800-207) | SC-7 | Zero Trust assumes no implicit trust in identity changes or controller-originated actions. |
| NIST SP 800-63 | Digital identity guidance informs assurance around non-human credential state changes. |
Alert on unexpected computer account changes and correlate them with controller context and identity ownership.
Related resources from NHI Mgmt Group
- How should security teams implement Client ID Metadata Documents?
- What makes Shai Hulud 2.0 different from a normal npm malware event?
- How should teams govern hybrid Active Directory and Entra ID at the same time?
- What is the difference between quarterly certification and event-driven access control?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 27, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org