Event Id | 4647 |
Source | Microsoft-Windows-Security-Auditing |
Description | User initiated logoff: Subject: Security ID:<Security ID> Account Name:<Account Name> Account Domain:<Domain Name> Logon ID:<Logon ID> |
Event Information | Cause : This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event. Resolution : NO user action is required. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.