Event ID 4634: Logoff
- Event ID
- 4634
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Logon
- Default logging
- Logged by default
What event 4634 means
Event 4634 is written when a logon session is destroyed. It carries the same TargetLogonId as the 4624 that opened the session, so the pair gives you a start and end time for any logon — interactive, network or service.
It is not a reliable "user clicked Sign out" record. For network logons (type 3) Windows tears the session down when the last connection closes, which can be seconds or hours later, and sometimes a 4634 is never written if the machine shuts down abruptly. When a user deliberately logs off an interactive or RDP session, event 4647 is written first and 4634 follows.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Logoff (Success). Enabled for Success in the default audit policy.
Short-lived network sessions produce 4624/4634 pairs within the same second; on file servers and DCs these pairs are the bulk of the log.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserSid | SID of the account whose session ended. |
| TargetUserName | Account whose session ended. |
| TargetDomainName | Domain or computer of that account. |
| TargetLogonId | Logon session ID — the same value as TargetLogonId in the matching 4624. |
| LogonType | Logon type of the session that ended (2, 3, 4, 5, 7, 10, 11…); see event 4624. |
Common benign sources
- Every normal session end, including machine accounts and services.
- Type 3 logoffs a few seconds after the matching logon on file servers and domain controllers.
What attackers do that produces it
- Not an attack signal on its own; it bounds the activity window of a suspicious session opened by a 4624.
- Very short type 10 or type 3 sessions from an unusual source may be automated tooling checking credentials.
Investigation tips
- Join on TargetLogonId with 4624 to compute session duration; missing 4634 may mean the session was still open at acquisition or the host crashed.
- For RDP, use 4779/4778 and the LocalSessionManager events 23/24 instead to see disconnects and reconnects.
- Everything logged with the same SubjectLogonId between the 4624 and the 4634 (4688, 4663, 5145…) belongs to that session.
Sigma rules for this event
1 SigmaHQ detection rules (release r2026-07-01) target this event.
- Info · 1
- InfoUser Logoff EventRule by frack113, SigmaHQ, DRL 1.1
Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.