User Account Deletion

The removal of a user, service, or machine account from an operating system, cloud identity management system, or directory service.

ID: DC0009
Domains: Enterprise
Version: 2.0
Created: 20 October 2021
Last Modified: 12 November 2025

Log Sources

Name Channel
esxi:hostd method=RemoveUser or esxcli system account remove invocation
m365:unified Remove-Mailbox, Set-Mailbox
WinEventLog:Security EventCode=4726, 4657

Detection Strategy