Event ID 4729 is generated by the Microsoft-Windows-Security-Auditing provider when Active Directory processes a request to remove a member from a security-enabled global group. This event occurs on domain controllers and is part of the advanced audit policy for account management.
The event contains comprehensive information about the group membership change, including the security identifier (SID) of the removed member, the target group name and domain, and the account that initiated the change. This level of detail makes it invaluable for security investigations and compliance reporting.
Global groups in Active Directory can contain users, computers, and other global groups from the same domain. When any of these objects are removed from a global group, Event ID 4729 is logged. The event helps administrators maintain visibility into group membership changes that could impact security boundaries and access control decisions.
This event is particularly critical in environments with strict compliance requirements, as it provides an audit trail for group membership changes. Security teams rely on this event to detect unauthorized modifications to privileged groups and to ensure that access removals are properly documented and authorized.