← Event ID reference
4624

An account was successfully logged on

  • Log: Security
  • Source: Microsoft-Windows-Security-Auditing
  • Logons
  • Info

What it means

A user, computer or service signed in. The Logon Type field tells you how: 2 interactive (at the keyboard), 3 network (file shares), 4 batch, 5 service, 7 unlock, 10 Remote Desktop, 11 cached credentials.

Why it matters

The baseline for "who accessed what, when". Type 10 logons from unexpected sources and logons outside business hours are worth alerting on.

What to do

  • Filter by Logon Type to separate people from services.
  • Check Source Network Address on type 3 and 10 logons.
  • Alert on admin accounts logging on to workstations.

Find it with PowerShell

Get-WinEvent -MaxEvents 20 -FilterHashtable @{
  LogName = 'Security'; Id = 4624
} | Select-Object TimeCreated, ProviderName, Message

Add -ComputerName SERVER to query another machine. Other event sources can reuse the same ID number, so check the ProviderName column.

Source

Seeing a lot of these? We can investigate, or alert you automatically through our monitoring.

Talk to us