windows server 2019 local user getting logoff on random time

Shafiq, Majid 0 Reputation points
2023-05-27T06:34:34.49+00:00

I have a very strange problem, and after having spent so many hours, still could not find solution.

I have windows server 2019 on which one application is running and it is using local user administrator account, however this account is getting logged off automatically with event id 4647 (user-initiated logoff) and as a result application also stops working, no one is doing this interactive log off. I have many gops applied based on customized CIS Benchmarking, but I have gone through all settings one by one, and I don't think any setting is doing this action.

Can you please suggest what's the cause of this?

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,600 questions
0 comments No comments
{count} votes

3 answers

Sort by: Most helpful
  1. Daisy Zhou 21,046 Reputation points Microsoft Vendor
    2023-05-29T06:33:10.1933333+00:00

    Hello Shafiq, Majid,

    Thank you for posting in our Q&A forum.

    1.The main difference with “4634(S): An account was logged off.” event is that 4647 event is generated when logoff procedure was initiated by specific account using logoff function, and 4634 event shows that session was terminated and no longer exists.

    You can check Account Name under Subject, who logoff the local administrator account.
    logoff

    https://learn.microsoft.com/en-us/windows/security/threat-protection/auditing/event-4647

    2.Also, is your machine in one domain or not? If so, when you change aonther local account, check if you have the same issue.

    3.If your machine is one domain, you can try to remove it from the domain and check if there is still such issue.

    4.Check if there is any script or schedule that does this thing.

    Hope the information above is helpful. If you have any question or concern, please feel free to let us know.

    Best Regards,
    Daisy Zhou

    ============================================

    If the Answer is helpful, please click "Accept Answer" and upvote it.

    0 comments No comments

  2. Shafiq, Majid 0 Reputation points
    2023-05-29T08:35:46.5366667+00:00

    Hi Daisy,

    Thanks for your message. yes, trying to narrow down the root cause, will use your suggestions.

    0 comments No comments

  3. Sandeep K 0 Reputation points
    2024-01-08T09:03:33.59+00:00

    I am seeing the similar issue in many our Server. I believe it started after we installed Azure Connected Machine Agent

    Not sure, if your is also same case

    0 comments No comments