Overview
Windows records successful and failed login attempts in the Security Event Log. Administrators can review these events to determine when users have accessed the cloud computer and to identify potential unauthorized sign-in attempts.
Prerequisites
- Administrator access to the cloud computer
- Access to Event Viewer
Steps
- Sign in to the cloud computer using an administrator account.
- Open Event Viewer.
- Navigate to:
Windows Logs > Security - In the right-hand panel, click Filter Current Log…
- In the <All Event IDs> field, enter:
4624for successful login attempts4625for failed login attempts
- Click OK to display the filtered results.
- Double-click any event to view detailed information such as:
- Username
- Logon type
- Date and time
Notes
- Event ID 4624 indicates a successful logon.
- Event ID 4625 indicates a failed logon attempt.
- Failed logons can help identify potential unauthorized access attempts.
- Security logs may be cleared depending on local retention policies, so older events may not always be available.
Comments
0 comments
Please sign in to leave a comment.