Skip to content
Security

Event ID 4800: Workstation locked

The workstation was lockedSecurity event 4800 records a user locking their workstation, with the account and logon session. Useful to tell when a user was really at the keyboard.
4800
Event ID
4800
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Needs configuration

What event 4800 means

Event 4800 is written when an interactive session is locked, whether by the user (Win+L, Ctrl+Alt+Del > Lock) or automatically by the screen saver or inactivity policy. It names the user (TargetUserName, TargetUserSid), the logon session (TargetLogonId) and the terminal session number (SessionId).

Lock and unlock events (4800/4801) build a presence timeline: activity inside a session while it was locked is unlikely to be the user at the keyboard. That helps separate a user's own actions from those of malware or a remote operator using the same session.

The event is part of the Other Logon/Logoff Events subcategory, which is not audited by default, so many machines will not have it.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success). Not enabled in the default audit policy.

Key fields

FieldWhat it tells you
TargetUserNameAccount whose session was locked.
TargetDomainNameDomain or computer name of that account.
TargetUserSidSID of that account.
TargetLogonIdLogon session that was locked; the same value appears in the session's 4624 and in 4801 on unlock.
SessionIdTerminal Services session number (console, RDP session) that was locked.

Common benign sources

  • Users locking their screen when leaving their desk.
  • Automatic locks from screen saver or inactivity timeouts.

What attackers do that produces it

  • Process activity (4688) or outbound connections in a session while it was locked suggests malware or a remote operator rather than the user.

Investigation tips

  • Build lock/unlock intervals per TargetLogonId and overlay other activity from the same session.
  • Pair with 4801 and 4624 LogonType 7 to confirm who unlocked the session and when.
  • Compare with RDP events (4778/4779, 24/25) when the session is remote.

Sigma rules for this event

1 SigmaHQ detection rules (release r2026-07-01) target this event.

  • Info · 1

Rules by their named authors, published by SigmaHQ under the Detection Rule License (DRL) 1.1.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading