Log-on type codes revealed
WindowSecurity.com -
The log-on/log-off category of the Windows security log gives you the ability to monitor all attempts to access the local computer. In this article I'll examine each log-on type in greater detail and show you how some other fields in Logon/Logoff events can be helpful for understanding the nature of a given log-on attempt.
Event IDs 528 and 540 signify a successful log-on, event ID 538 a log-off and all the other events in this category identify different reasons for a log-on failure. However, just knowing about a successful or failed log-on attempt doesn't fill in the whole picture. Because of all the services Windows offers, there are many different ways you can log on to a computer, such as interactively at the computer's local keyboard and screen, over the network through a drive mapping or through terminal services (aka remote desktop) or through IIS. Thankfully, log-on/log-off events specify the Logon Type code, which reveals the type of log-on that prompted the event.
Log-on Type 2: Interactive
This is what occurs to you first when you think of log-ons, that is, a log-on at the console of a computer. You'll see these types of log-ons when a user attempts to log on at the local keyboard and screen whether with a domain account or a local account from the computer's local SAM.
To tell the difference between an attempt to log on with a local or domain account, look for the domain or computer name preceding the user name in the event's description. Don't forget that log-on's through a KVM over IP component or a server's proprietary "lights-out" remote KVM feature are still interactive log-ons from the standpoint of Windows and will be logged as such.
Log-on Type 3: Network
Windows logs log-on type 3 in most cases when you access a computer from elsewhere on the network. One of the most common sources of log-on events with log-on type 3 is connections to shared folders or printers. But other over-the-network log-ons are classed as log-on type 3 as well such as most log-ons to IIS. (The exception is basic authentication which is explained in Log-on Type 8 below.)
Log-on Type 4: Batch
When Windows executes a scheduled task, the Scheduled Task service first creates a new log-on session for the task so that it can run under the authority of the user account specified when the task was created. When this log-on attempt occurs, Windows logs it as log-on type 4. Other job scheduling systems, depending on their design, may
Reprinted with permission from
Story copyright 2006 WindowSecurity.com. All rights reserved.
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Sustaining SOX Compliance: Best Practices to Mitigate Risk, Automate Compliance, and Reduce Costs
Since the adoption of SOX, much has been learned about IT compliance. Discover how to make SOX efforts more effective in "Sustaining Sox...
Why Compliance Pays
This OnDemand webcast explores the relationship that firms with best compliance records have higher revenue, greater customer retention, lower financial losses from data...
IDC White Paper: CCM for IT Compliance and Risk Management
Learn from industry analysts how IT organizations are using configuration management to meet compliance requirements and instill best practices. Find out how these...
Best Practices for Managing Business Risks from the Use of IT
(Source: Symantec) Based on exhaustive benchmarks conducted by the IT Policy Compliance, this session highlights the relationship between business risks and use of...
Keep it Clean: Maintaining the Integrity of your CMDB through Change Detection
Learn how configuration drift can challenge configuration management database (CMDB) integrity and how a configuration audit tool and an effective change management process...
Managing And Protecting Your Ever Increasing Mobile Assets
(Source: Absolute Software) Your users are becoming more mobile each day. This is great for productivity - yet challenging for IT control. Natalie...
The Tripwire HIPAA Solution: Meeting the Security Standards Set Forth in Section 164
HIPAA requires businesses that handle personal health information (PHI) to set up strong controls to ensure the security and integrity of that information....
Sun OpenSSO Enterprise Webinar
(Source: Sun) This webinar replay discusses Sun OpenSSO Enterprise innovation--the single, open-source solution that helps your business solve the challenges around internal access...
Configuration Assessment: Choosing the Right Solution
Configuration assessment lets businesses proactively secure their IT infrastructure and achieve compliance with important industry standards and regulations. Learn why configuration assessment is...
Agile Enterprise Content Management (ECM) for Rapid ROI
(Source: IBM) Content rich business processes are a core feature of daily operations at just about any organization today. Very often these essential...
Subscribe to Computerworld
