However, if you're using Remote Desktop Connection to control that work PC you may be able to pull the logon / logoff times from the Event Viewer. Logon GUID: Supposedly you should be able to correlate logon events on this computer with corresonding authentication events on the domain controller using this GUID.Such as linking 4624 on the member You can see (graphical dashboards) and report who is connected, from which system, since what time, for how long etc.

Remote Desktop Services Events (by Event ID) in Windows Server 2008 R2 Updated: February 10, 2010Applies To: Windows Server 2008 R2 The following is a list of Remote Desktop Services events The events can be viewed by using Event Viewer.

Windows 7 Logon Event Id Hot Network Questions Differential high voltage measurement using a transformer What would be your next deduction in this game of Minesweeper? Please check the Event Viewer tree on the left side under "Applications and Services Logs -> Windows -> TerminalServices-*" where * is all of the logs there.

The authentication information fields provide detailed information about this specific logon request. Subject: Account Name: Administrator Account Domain: WIN-R9H529RIO4Y Logon ID: 0x169e9 Session: Session Name: RDP-Tcp#0 Additional Information: Client Name: XPEDIT Client Address: This event is

Most often indicates a logon to IIS with "basic authentication") See this article for more information. 9 NewCredentials such as with RunAs or mapping a network drive with alternate credentials.

Workstation Name: the computer name of the computer where the user is physically present in most cases unless this logon was intitiated by a server application acting on behalf of the With console logons and Fast User Switching the session name will be "Console" and Client Name and Address will be "unknown".

Table 1:  Event ID 4624 Logon Types Logon Type Description 2 Physical or interactive logon 3 Network connection, I.E Net Use 4 Schedule task logon 5 Service Startup 7 Password unlocked Detailed Authentication Information: Logon Process: (see 4611) CredPro indicates a logoninitiated by User Account Control Authentication Package: (see 4610 or 4622) Transited Services: This has to do with server applications that Logon Type 9 – NewCredentials If you use the RunAs command to start a program under a different user account and specify the /netonly switch, Windows records a logon/logoff event with

You can distinguish between instances of this event associated with Fast User Switching and Remote Desktop by Client Name: and Client Address: which in the case of Remote Desktop will normally For troubleshooting documentation for other server roles (for example, Active Directory Rights Management Services) and Server Fundamentals (for example, Core Security) in Windows Server 2008 R2, see Troubleshoot Windows Server 2008 R2 (http://go.microsoft.com/fwlink/?LinkId=182372). Procedure: Security Event Log Extraction When examining the event logs, we are specifically looking at Security Event record ID 4624, which is recorded for any type of logon to the machine.

Security ID: the SID of the account Account Name: Logon name of the account Account Domain: Domain name of the account (pre-Win2k domain name) Logon ID: a semi-unique (unique between reboots) scheduled task) 5 Service (Service startup) 7 Unlock (i.e. This level, which will work with WMI calls but may constitute an unnecessary security risk, is supported only under Windows 2000.

