RDP Event ID 1149: Connection authenticated
- Event ID
- 1149
- Channel
- Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
- Provider
- Microsoft-Windows-TerminalServices-RemoteConnectionManager
- Log file
- Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx
- Category
- Remote access
- Default logging
- Logged by default
What event 1149 means
Event 1149 is written on the RDP server when a client's Remote Desktop connection passes the network-level step. Despite the message text "User authentication succeeded", it does not prove that a desktop session was opened: with Network Level Authentication (NLA) it means the credentials were accepted at the network level, and without NLA it can be logged as soon as the connection is made, before any password is checked.
Its value is the source: Param3 holds the client IP address, together with the user name and domain the client sent. The log is enabled by default and often survives when the Security log has rolled over or was cleared, so it is frequently the best surviving record of who connected over RDP and from where.
Confirm the actual logon with Security 4624 (LogonType 10, or 7 for a reconnect to a locked session) and LocalSessionManager 21, 22 or 25.
When it is logged
None — the Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational channel is enabled by default on hosts that accept Remote Desktop connections.
The data sits under UserData/EventXML as Param1, Param2 and Param3 rather than named EventData fields.
Key fields
| Field | What it tells you |
|---|---|
| Param1 | User name supplied by the client. |
| Param2 | Domain supplied by the client (can be empty or the computer name for local accounts). |
| Param3 | Source IP address of the RDP client. If an RDP gateway or tunnel is in use, this is the gateway or tunnel endpoint. |
Common benign sources
- Administrators and users connecting over RDP from their usual workstations or jump hosts.
- Remote support staff and monitoring that tests RDP availability with credentials.
What attackers do that produces it
- External RDP access with valid or brute-forced credentials — public source IPs in Param3.
- Lateral movement over RDP inside the network, often from a server or workstation that never RDPs elsewhere.
- RDP tunneled through a compromised host (for example with SSH or proxy tools) — Param3 is then a local address such as
127.0.0.1or::1.
Investigation tips
- List Param3 values per user and flag first-seen IPs, public IPs and loopback addresses.
- Confirm each connection with Security 4624 type 10 and LocalSessionManager 21/25 at the same time; a 1149 without a logon may be a failed or aborted attempt.
- Use this log to fill gaps when the Security log has been cleared (1102) — it is a separate file.
- On the source host, the RDPClient log (1024, 1102) shows outbound connections toward this server.
MITRE ATT&CK techniques
MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.