Quantcast
Channel: Active questions tagged windows - Super User
Viewing all articles
Browse latest Browse all 10454

How to determine why Windows security event log ID 4624 are occurring and what is being done on my computer?

$
0
0

I work for a smaller company that has an IT guy that is a real hot-head, who thinks he’s God. I’ve noticed lately that I have a bunch of event ID 4624 (successful logon) events popping up in my Windows security event log with his user name. It doesn’t appear to be some scheduled job because they are random throughout the day. I’m seeing 10-20 of these logon events with the IT guy’s user name per day.

What could these logon events be?

If he is “secretly” logging on to my computer, how can I determine what he’s doing?

Here's a little snippet of the event text:

Log Name:      SecuritySource:        Microsoft-Windows-Security-AuditingDate:          5/14/2019 8:17:04 AMEvent ID:      4624Task Category: LogonLevel:         InformationKeywords:      Audit SuccessUser:          N/ADescription:An account was successfully logged on.Subject:    Security ID:        NULL SID    Account Name:       -    Account Domain:     -    Logon ID:       0x0Logon Information:    Logon Type:     3    Restricted Admin Mode:  -    Virtual Account:        No    Elevated Token:     NoNew Logon:    Security ID:        domain\ITguyuser    Account Name:       ITguyuser    Account Domain:     domain

Viewing all articles
Browse latest Browse all 10454

Trending Articles