Skip to content
RDP LocalSessionManager

RDP Event ID 21: Session logon succeeded

Remote Desktop Services: Session logon succeededRDP event 21 confirms a session logon on the target: user, session ID and source network address ("LOCAL" for console logons).
21
Event ID
21
Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Log file
Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 21 means

Event 21 is written by the Local Session Manager when a user session is created and the logon completes — for Remote Desktop and for local console logons alike. The Address field separates them: an IP address for RDP, LOCAL for the console.

Where 1149 only shows that an RDP connection got through, 21 shows that a desktop session was actually created for the user. It is typically followed by 22 (shell start) and, when the session ends, by 23 (logoff) or 24 (disconnect). A reconnection to an existing session is logged as 25 instead.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-TerminalServices-LocalSessionManager/Operational channel is enabled by default.

Fields sit under UserData/EventXML (User, SessionID, Address).

Key fields

FieldWhat it tells you
UserAccount that logged on, in DOMAIN\user form.
SessionIDTerminal Services session number; ties together 21, 22, 23, 24 and 25 for the same session.
AddressSource IP address of the RDP client, or LOCAL for console logons.

Common benign sources

  • Interactive console logons and routine RDP logons by administrators and users.
  • Jump-host and VDI environments with many RDP sessions per day.

What attackers do that produces it

  • Hands-on-keyboard access over RDP with stolen credentials, from external IPs or internal hosts that do not normally RDP.
  • Tunneled RDP, where Address shows 127.0.0.1 or ::1.

Investigation tips

  • Pair with Security 4624 LogonType 10 at the same second to get the logon ID and authentication details.
  • Group sessions by SessionID to measure duration (21 → 23/24).
  • Compare Address with the 1149 entries just before; they should match.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1078 Valid AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • High · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideRDP forensics: the complete event-log picture

Sources and further reading