Event ID 4624 – An Account Was Successfully Logged On
Event ID | 4624 |
Category | Logon/Logoff |
Sub-Category | Audit Logon |
Type | Success Audit |
Description | An account was successfully logged on to |
Event 4624 is generated by the computer where a logon session was created successfully. This applies to both local and remote logons.
This log data provides the following information:
- Security ID
- Account Name
- Account Domain
- Logon ID
Why does event ID 4624 need to be monitored?
- To monitor actions of high value accounts
- To detect anomalies and malicious actions
- To ensure non-active, external, and restricted accounts are not used
- To ensure that only white-listed accounts perform certain specific actions
- To enforce conventions and compliances
Pro Tip:
With in-depth reports, real-time alerts, and graphical displays, ADAudit Plus tracks successful logon attempts by local users, helping you meet your security, operational, and compliance needs with absolute ease.
Event 4624 applies to the following operating systems:
- Windows 2008 R2 and 7
- Windows 2012 R2 and 8.1
- Windows 2016 and 10
Corresponding events in Windows 2003 and before: 528 and 540.
Explore Active Directory auditing and reporting with ADAudit Plus.
- Related Products
- ADManager Plus Active Directory Management & Reporting
- ADAudit Plus Real-time Active Directory Auditing and UBA
- EventLog Analyzer Real-time Log Analysis & Reporting
- ADSelfService Plus Self-Service Password Management
- AD360 Integrated Identity & Access Management
- Log360 (On-Premise | Cloud) Comprehensive SIEM and UEBA
- AD Free Tools Active Directory FREE Tools