Skip to content
Security

Event ID 4801: Workstation unlocked

The workstation was unlockedSecurity event 4801 records a user unlocking their workstation, with the account and logon session. Pairs with 4800 to show when the user was present.
4801
Event ID
4801
Channel
Security
Provider
Microsoft-Windows-Security-Auditing
Log file
Security.evtx
Category
Logon
Default logging
Needs configuration

What event 4801 means

Event 4801 is written when a locked interactive session is unlocked. Like 4800 it records the user (TargetUserName, TargetUserSid), the logon session (TargetLogonId) and the terminal session number (SessionId).

An unlock also involves an authentication, which is logged separately as a 4624 with LogonType 7 (or a 4625 if the password was wrong). 4801 is the simpler marker that the session is back in use, and it closes the interval opened by the matching 4800.

Unlocks at unusual hours, or an unlock of a session with no matching user presence (badge records, VPN logs), can indicate someone else using the account at the console or over RDP.

When it is logged

Audit policy / configuration

Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success). Not enabled in the default audit policy.

Key fields

FieldWhat it tells you
TargetUserNameAccount whose session was unlocked.
TargetDomainNameDomain or computer name of that account.
TargetUserSidSID of that account.
TargetLogonIdLogon session that was unlocked; matches the 4800 and the original 4624 of the session.
SessionIdTerminal Services session number that was unlocked.

Common benign sources

  • Users returning to their desk and unlocking the screen.
  • Users reconnecting to a locked RDP session.

What attackers do that produces it

  • Someone with the user's password unlocking a session at the console or over RDP at an unusual time.

Investigation tips

  • Match with the preceding 4800 on the same TargetLogonId to measure the absence interval.
  • Check the 4624 LogonType 7 at the same time for authentication details, and 4625 for failed unlock attempts.
  • For remote sessions, correlate with 4778 and RDP events 25 / 1149 to get the client address.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading