Skip to content
RDP RemoteConnectionManager

RDP Event ID 1149: Connection authenticated

Remote Desktop Services: User authentication succeededRDP event 1149 records an inbound Remote Desktop connection with user, domain and source IP. It means the network connection succeeded, not the logon.
1149
Event ID
1149
Channel
Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational
Provider
Microsoft-Windows-TerminalServices-RemoteConnectionManager
Log file
Microsoft-Windows-TerminalServices-RemoteConnectionManager%4Operational.evtx
Category
Remote access
Default logging
Logged by default

What event 1149 means

Event 1149 is written on the RDP server when a client's Remote Desktop connection passes the network-level step. Despite the message text "User authentication succeeded", it does not prove that a desktop session was opened: with Network Level Authentication (NLA) it means the credentials were accepted at the network level, and without NLA it can be logged as soon as the connection is made, before any password is checked.

Its value is the source: Param3 holds the client IP address, together with the user name and domain the client sent. The log is enabled by default and often survives when the Security log has rolled over or was cleared, so it is frequently the best surviving record of who connected over RDP and from where.

Confirm the actual logon with Security 4624 (LogonType 10, or 7 for a reconnect to a locked session) and LocalSessionManager 21, 22 or 25.

When it is logged

Audit policy / configuration

None — the Microsoft-Windows-TerminalServices-RemoteConnectionManager/Operational channel is enabled by default on hosts that accept Remote Desktop connections.

The data sits under UserData/EventXML as Param1, Param2 and Param3 rather than named EventData fields.

Key fields

FieldWhat it tells you
Param1User name supplied by the client.
Param2Domain supplied by the client (can be empty or the computer name for local accounts).
Param3Source IP address of the RDP client. If an RDP gateway or tunnel is in use, this is the gateway or tunnel endpoint.

Common benign sources

  • Administrators and users connecting over RDP from their usual workstations or jump hosts.
  • Remote support staff and monitoring that tests RDP availability with credentials.

What attackers do that produces it

  • External RDP access with valid or brute-forced credentials — public source IPs in Param3.
  • Lateral movement over RDP inside the network, often from a server or workstation that never RDPs elsewhere.
  • RDP tunneled through a compromised host (for example with SSH or proxy tools) — Param3 is then a local address such as 127.0.0.1 or ::1.

Investigation tips

  • List Param3 values per user and flag first-seen IPs, public IPs and loopback addresses.
  • Confirm each connection with Security 4624 type 10 and LocalSessionManager 21/25 at the same time; a 1149 without a logon may be a failed or aborted attempt.
  • Use this log to fill gaps when the Security log has been cleared (1102) — it is a separate file.
  • On the source host, the RDPClient log (1024, 1102) shows outbound connections toward this server.

MITRE ATT&CK techniques

TechniqueTactics
T1021.001 Remote Services: Remote Desktop ProtocolLateral Movement
T1133 External Remote ServicesPersistence, Initial Access
T1078 Valid AccountsStealth, Persistence, Privilege Escalation, Initial Access

MITRE ATT&CK v19.2. Technique and tactic names are MITRE's.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

In-depth guideRDP forensics: the complete event-log picture

Sources and further reading