6

We have a pool of develop machines where developers log in through RDP and usually they doesn't log off but just disconnect. As local administrator I can force the log off but I would like to check when the user disconnected.

From task manager I can see only the user name and its status

enter image description here

Is there a way to discover when the user disconnected using task manager, powershell, cmd or whatever?

Naigel
  • 8,244
  • 15
  • 65
  • 99

4 Answers4

9

You can use windows command query user UserName /server:ServerName or you can just enter query user /server:ServerName to find out all active or disconnected sessions.

Below is the sample output, I have blurred out my info for privacy:

enter image description here

I have also created a PowerShell script to do this task automatically, here is the link Powershell to find out disconnected RDP session and log off at the same time

Community
  • 1
  • 1
LT-
  • 582
  • 2
  • 5
  • 18
2

As far as I know this is not in the security logs. The correct place to look for is in Microsoft Event Viewer under Applications and Services Logs => Microsoft => Windows => TerminalServices-LocalSessionManager => Operational and then under the Operational logs.

The eventID to look for is ID24 (disconnected user session). EventID 25 is a reconnect.

Naigel
  • 8,244
  • 15
  • 65
  • 99
bluuf
  • 882
  • 1
  • 6
  • 13
  • perfect, thank you! I corrected the path, it was incomplete. In that view I can find only real user connection, exactly what I was looking for – Naigel Aug 24 '15 at 14:20
1

You can start the Windows Event Viewer and check under Windows logs --> Security. Filter by 'Task Category = Logoff'.

You can export it to xml for easier reading.

enter image description here

Naigel
  • 8,244
  • 15
  • 65
  • 99
Nissim
  • 6,106
  • 5
  • 47
  • 72
  • Why don't you edit your previous answer and include this, instead of posting two answers (which are the same)? – Patrick Aug 24 '15 at 08:46
  • ok answer nearly correct, of course I can't find the logoff because he didn't logged off, but just disconnected. Anyway I can't find any details, my security logs history is just too short – Naigel Aug 24 '15 at 09:17
  • 1
    a Logoff is something completely different as a disconnect in RDP. – bluuf Aug 24 '15 at 12:07
0

Start-->Run-->Eventvwr-->Windows logs-->Security. Filter by 'Task Category = Logoff'

Nissim
  • 6,106
  • 5
  • 47
  • 72