WinSecWiki > Security Settings > Local Policies > Audit Policy > Audit Logon > Logoff

Logoff

This category records only logoff events. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
4634 An account was logged off.
4647 User initiated logoff

Back to top

 

Upcoming Webinars
  • AD Certificate Services: A Massive Chunk of Windows Security Functionality Finally Gets the Security Research It Deserves
  • Linux Security: Locking Down Admin Access with SSH and Sudo
  • Understanding Broken Object Level Authorization: The Quiet Access Control Failure Undermining Today’s Apps
  • Patching 3rd Party Apps on PCs Managed by Intune
Additional Resources
    Audit Logon
    •Logon
    •Logoff
    •Account Lockout
    •IPsec Main
    •IPsec Quick
    •IPsec Extended
    •Special Logon
    •Other Logon/Logoff
    •NPS

     
     
    User name:
    Password:
      / Forgot?
      Register
    January 2026
    Patch Tuesday
    "Patch Tuesday - Starting 2026 with a Bang; 3 Zero Days " - sponsored by LOGbinder and Supercharger
    .
    Tweet
    Follow @randyfsmith
    About | Newsletter | Contact Ultimate IT Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, Inc. All rights reserved.
    Disclaimer: We do our best to provide quality information and expert commentary but use all information at your own risk. For complaints, please contact abuse@ultimatewindowssecurity.com.
    Terms of Use | Privacy |
    Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.