Event ID 4801: Workstation unlocked
- Event ID
- 4801
- Channel
- Security
- Provider
- Microsoft-Windows-Security-Auditing
- Log file
- Security.evtx
- Category
- Logon
- Default logging
- Needs configuration
What event 4801 means
Event 4801 is written when a locked interactive session is unlocked. Like 4800 it records the user (TargetUserName, TargetUserSid), the logon session (TargetLogonId) and the terminal session number (SessionId).
An unlock also involves an authentication, which is logged separately as a 4624 with LogonType 7 (or a 4625 if the password was wrong). 4801 is the simpler marker that the session is back in use, and it closes the interval opened by the matching 4800.
Unlocks at unusual hours, or an unlock of a session with no matching user presence (badge records, VPN logs), can indicate someone else using the account at the console or over RDP.
When it is logged
Advanced Audit Policy Configuration > Logon/Logoff > Audit Other Logon/Logoff Events (Success). Not enabled in the default audit policy.
Key fields
| Field | What it tells you |
|---|---|
| TargetUserName | Account whose session was unlocked. |
| TargetDomainName | Domain or computer name of that account. |
| TargetUserSid | SID of that account. |
| TargetLogonId | Logon session that was unlocked; matches the 4800 and the original 4624 of the session. |
| SessionId | Terminal Services session number that was unlocked. |
Common benign sources
- Users returning to their desk and unlocking the screen.
- Users reconnecting to a locked RDP session.
What attackers do that produces it
- Someone with the user's password unlocking a session at the console or over RDP at an unusual time.
Investigation tips
- Match with the preceding 4800 on the same TargetLogonId to measure the absence interval.
- Check the 4624 LogonType 7 at the same time for authentication details, and 4625 for failed unlock attempts.
- For remote sessions, correlate with 4778 and RDP events 25 / 1149 to get the client address.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.