Skip to content
Security

Event ID 4634: Logoff

An account was logged offEvent 4634 marks the end of a logon session. Match its TargetLogonId to a 4624 to measure how long a session lasted.
4634
Event ID
4634
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Logged by default

What event 4634 means

Event 4634 is written when a logon session is destroyed. It carries the same TargetLogonId as the 4624 that opened the session, so the pair gives you a start and end time for any logon — interactive, network or service.

It is not a reliable "user clicked Sign out" record. For network logons (type 3) Windows tears the session down when the last connection closes, which can be seconds or hours later, and sometimes a 4634 is never written if the machine shuts down abruptly. When a user deliberately logs off an interactive or RDP session, event 4647 is written first and 4634 follows.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Logoff (Success). Enabled for Success in the default audit policy.

Short-lived network sessions produce 4624/4634 pairs within the same second; on file servers and DCs these pairs are the bulk of the log.

Key fields

FieldWhat it tells you
TargetUserSidSID of the account whose session ended.
TargetUserNameAccount whose session ended.
TargetDomainNameDomain or computer of that account.
TargetLogonIdLogon session ID — the same value as TargetLogonId in the matching 4624.
LogonTypeLogon type of the session that ended (2, 3, 4, 5, 7, 10, 11…); see event 4624.

Common benign sources

  • Every normal session end, including machine accounts and services.
  • Type 3 logoffs a few seconds after the matching logon on file servers and domain controllers.

What attackers do that produces it

  • Not an attack signal on its own; it bounds the activity window of a suspicious session opened by a 4624.
  • Very short type 10 or type 3 sessions from an unusual source may be automated tooling checking credentials.

Investigation tips

  • Join on TargetLogonId with 4624 to compute session duration; missing 4634 may mean the session was still open at acquisition or the host crashed.
  • For RDP, use 4779/4778 and the LocalSessionManager events 23/24 instead to see disconnects and reconnects.
  • Everything logged with the same SubjectLogonId between the 4624 and the 4634 (4688, 4663, 5145…) belongs to that session.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading