WinSecWiki > Security Settings > Advanced Audit Policies > Logon/Logoff > Logoff

Audit Logoff

This category records only logoff events. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
4634 An account was logged off.
4647 User initiated logoff

Back to top

 

Additional Resources