Windows Security Logon Event ID 4800: Workstation Lock After Inactivity

Locked Workstation

FreeReviewedSigma · Informational · v2
Product
windows
Service
security
Author
Alexandr Yampolskyi, SOC Prime (SigmaHQ), DRL 1.1
Published
2019-03-26
Updated
2026-07-31

What it detects

This rule identifies Windows Security events (Event ID 4800) indicating a workstation session was locked automatically after a period of inactivity. Locking sessions helps reduce risk of unauthorized access, but unexpected or frequent lock events can also be a sign of suspicious user activity or environmental changes. It relies on Windows Security log telemetry for EventID 4800 records.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.