Skip to content
RDP LocalSessionManager

RDP Event ID 40: Session disconnect reason

Session has been disconnected, reason codeRDP event 40 gives the reason code for a session disconnect, telling user-initiated disconnects from replaced connections.
40
Event ID
40
Channel
Microsoft-Windows-TerminalServices-LocalSessionManager/Operational
Provider
Microsoft-Windows-TerminalServices-LocalSessionManager
Log file
Microsoft-Windows-TerminalServices-LocalSessionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 40 means

Event 40 accompanies session disconnects with a numeric reason code. It explains why the 24 happened: the user closed the connection, a newer connection replaced it, or the reason is unknown.

Reason codes are most useful in aggregate: many disconnects with "connection replaced" for one session mean the same account was being used from multiple clients in turn.

When it is logged

Audit policy / configuration

None — the LocalSessionManager/Operational channel is enabled by default.

Key fields

FieldWhat it tells you
SessionSession number that was disconnected.
ReasonDisconnect reason code.
ValueMeaning
0No additional information is available.
5The client's connection was replaced by another connection.
11User activity initiated the disconnect (the user disconnected).

Common benign sources

  • Users closing the client (reason 11) or reconnecting from another device (reason 5).

What attackers do that produces it

  • Frequent reason 5 disconnects of an admin session can indicate someone else attaching to it.

Investigation tips

  • Correlate with 24 (disconnect) and 25 or 39 around the same time for the same session.
  • Chart reason codes per session over time; repeated reason 5 on one admin session is the pattern to explain.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading