Skip to content
Security

Event ID 4647: User-initiated logoff

User initiated logoffEvent 4647 is logged when a user actively signs out of an interactive or RDP session, before the session teardown event 4634.
4647
Event ID
4647
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Logged by default

What event 4647 means

Event 4647 records a deliberate sign-out: the user chose Sign out, ran logoff, or a script called the logoff API for an interactive (type 2), RDP (type 10) or cached (type 11) session. It is logged when the logoff starts, while 4634 is logged when the session is actually destroyed, so both usually appear a moment apart with the same logon ID.

Network logons never produce 4647 — they end with 4634 only. Because 4647 requires an interactive user action, it is a cleaner "end of hands-on-keyboard session" marker than 4634.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Logoff (Success). Enabled for Success in the default audit policy.

Key fields

FieldWhat it tells you
TargetUserSidSID of the user who logged off.
TargetUserNameUser who logged off.
TargetDomainNameDomain or computer of the user.
TargetLogonIdLogon session ID; matches the 4624 that started the session and the 4634 that follows.

Common benign sources

  • Users signing out at the end of the day or of an RDP session.
  • Administrators logging off after maintenance.

What attackers do that produces it

  • An intruder closing an RDP session after hands-on activity — the 4647 time marks when they left.

Investigation tips

  • Pair TargetLogonId with 4624 (type 2 or 10) to reconstruct interactive session windows.
  • A 4624 type 10 without a later 4647 means the session was disconnected rather than logged off — check 4779 and LocalSessionManager 24.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading