WinSecWiki > Security Settings > Local Policies > Audit Policy > Audit Logon > Logoff

Logoff

This category records only logoff events. To configure this on Server 2008 and Vista you must use auditpol. Windows 7 and Server 2008 R2 and later can use Group Policy.

Coverage on events generated by this category are currently in the Security Log Encyclopedia:

Event ID Title
4634 An account was logged off.
4647 User initiated logoff

Back to top

 

Upcoming Webinars
  • AI Security Hands-On: Understanding and Red Teaming the LLM as a Black Box
  • Rethinking Privileged Access for the Age of AI-Powered Attacks
  • Inside Entra ID Authentication: How Tokens, MFA, and Conditional Access Work and Where Attackers Break the Chain
  • Understanding Entra Privileged Identity Management, What PIM Covers and Where It Stops
Additional Resources
    Audit Logon
    •Logon
    •Logoff
    •Account Lockout
    •IPsec Main
    •IPsec Quick
    •IPsec Extended
    •Special Logon
    •Other Logon/Logoff
    •NPS

     
     
    User name:
    Password:
      / Forgot?
      Register
    August 2026
    Patch Tuesday
    "Patch Tuesday - Three Zero Days this Month " - sponsored by Supercharger
    Home
    Tweet
    Follow @randyfsmith
    About | Newsletter | Contact Ultimate IT Security is a division of Monterey Technology Group, Inc. ©2006-2026 Monterey Technology Group, Inc. All rights reserved.
    Disclaimer: We do our best to provide quality information and expert commentary but use all information at your own risk. For complaints, please contact abuse@ultimatewindowssecurity.com.
    Terms of Use | Privacy |
    Cookies help us deliver the best experience on our website. By using our website, you agree to the use of cookies.