Event Id | 4800 |
Source | Microsoft-Windows-Security-Auditing |
Description | The workstation was locked. Subject: Security ID: <Security ID> Account Name: <Account Name> Account Domain: <Domain Name> Logon ID: <Logon ID> Session ID: <Session ID> |
Event Information | Cause : This event is logged when a user manually locks his workstation or the workstation automatically locks its console after a period of inactivity. |
Reference Links |
Catch threats immediately
We work side-by-side with you to rapidly detect cyberthreats
and thwart attacks before they cause damage.