WinSecWiki > Security Settings > Local Policies > Audit Policy > Audit Logon > Logoff

Logoff

This category records only logoff events. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
4634 An account was logged off.
4647 User initiated logoff

Back to top

 

Additional Resources