Windows event id 4800

When either a user manually locks his workstation or the workstation automatically locks its console after a period of inactivity this event is logged.

To find out when the user returned and unlocked the workstation look for event ID 4801.

If a screen saver is used, there is a relationship between this event and 4802/4803  See event ID 4802 for an explanation of the sequence of events.


Description Fields in
4800

Subject:

The user and logon session involved.

  • Security ID:  The SID of the account.
  • Account Name: The account logon name.
  • Account Domain: The domain or — in the case of local accounts — computer name.
  • Logon ID is a semi-unique (unique between reboots) number that identifies the logon session.  Logon ID allows you to correlate backwards to the logon event (4624) as well as with other events logged during the same logon session.

Stay up-to-date on the Latest in Cybersecurity

Sign up for the Ultimate IT Security newsletter
to hear about the latest webinars, patches, CVEs, attacks, and more.

The workstation was locked

The workstation was locked.

Subject:
    Security ID:    %1
    Account Name:   %2
    Account Domain: %3
    Logon ID:       %4
    Session ID:     %5

This event is generated when a workstation was locked.

ISO 27001:2013 A.11.2.8
NIST 800-171: 3.1.10
NIST SP 800-53: AC-11
CMMC v2 L2: AC.L2-3.1.10

Name Field Insertion String OS Example
Security ID TargetUserSid %1 Any DOMAIN\UserName
Account Name TargetUserName %2 Any UserName

Account Domain TargetDomainName %3 Any DOMAIN
Logon ID TargetLogonId %4 Any 0x759a9

Session ID SessionId %5 Any 3


Lookup Audit Policy Configuration Settings


C:\> AuditPol.exe /get /subcategory:"Other Logon/Logoff Events"



LEFT/RIGHT arrow keys for navigation

Back to List

Event ID: 

Category: 

Subcategory: 

Other Logon/Logoff Events

Supported on: 

Windows Vista, Windows Server 2008

The workstation was locked.

Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4
Session ID: %5

Related content

Event Details
User Activity->Logons->Successful Logons->Windows 2008->EventID 4800 — The workstation was locked.

EventID 4800 — The workstation was locked.
Linked Event: EventID 4800 — The workstation was locked.
 Sample:
        The workstation was locked.

        Subject:
        Security ID:		%1
        Account Name:		%2
        Account Domain:		%3
        Logon ID:		%4
        Session ID:	%5
      
Log Type: Windows Event Log
 Uniquely Identified By:
Log Name: Security
Filtering Field Equals to Value
OSVersion Windows Vista (2008)
Windows 7 (2008 R2)
Windows 8 (2012)
Windows 8.1 (2012 R2)
Windows 10 (2016)
Category Logon/Logoff
Source Microsoft-Windows-Security-Auditing
TaskCategory Other Logon/Logoff Events
EventId 4800
Field Matching
Field Description Stored in Sample Value
When At what date and time a user activity originated in the system. DateTime 10.10.2000 19:00:00
Who Account or user name under which the activity occured. Subject: Account Name
What The type of activity occurred (e.g. Logon, Password Changed, etc.) «Workstation Locked» Workstation Locked
Where The name of the workstation/server where the activity was logged. Computer DC1
Where From The name of the workstation/server where the activity was initiated from. 10.10.10.10
Severity Specify the seriousness of the event. «Medium» Medium
WhoDomain Subject: Account Domain
WhereDomain
Result Successful or Failed. «Successful» Successful
Failure Reason «Successful» Successful


Event submitted by
Event Log Doctor

Event ID:

4800

Source:

Security

Category:

Other Logon/Logoff Events

Message:

The workstation was locked.


Subject:

Security ID: GOTHAM\bat.man

Account Name: bat.man

Account Domain: GOTHAM

Logon ID: 0x19a2e6

Session ID: 1


System32 Reference

Windows Security Event ID 4800


Solution by
Event Log Doctor

2013-02-18 17:47:23 UTC

Windows Vista and later log this event when a user locks the workstation.


User Information

Only an Email address is required for returning users.

Email:

Name / Alias:

Hide Name


Solution

Your solution: *


Additional Links

Name:

URL:

Понравилась статья? Поделить с друзьями:
0 0 голоса
Рейтинг статьи
Подписаться
Уведомить о
guest

0 комментариев
Старые
Новые Популярные
Межтекстовые Отзывы
Посмотреть все комментарии
  • Microsoft usbccid smartcard reader windows 7
  • Windows 10 pro x64 original iso
  • Ati mobility radeon hd 5145 драйвер windows 10 64
  • Не работает сенсорная клавиатура windows 11
  • Как сделать windows memory diagnostic