Windows Server Security Event 4647

Windows Server Security Event 4647:

User initiated logoff:

Subject:
Security ID: %1
Account Name: %2
Account Domain: %3
Logon ID: %4

This event is generated when a logoff is initiated but the token reference count is not zero and the logon session cannot be destroyed. No further user-initiated activity can occur. This event can be interpreted as a logoff event.

Leave a Reply

Your email address will not be published. Required fields are marked *