You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
event id 4625
About this tag
Event ID 4625 is a Windows Security log event that records failed sign-in attempts. On Windows 10 and Windows 11, this event can help identify forgotten passwords, misconfigured services, Remote Desktop probing, or potential break-in attempts. To capture event ID 4625, you must enable the appropriate audit policy for logon events. Once enabled, failed logon attempts are logged in the Security event log and can be reviewed using Event Viewer. This tag covers tutorials on enabling audit policies, testing failed logon auditing, and interpreting event ID 4625 entries. It is relevant for users managing security auditing on Windows 10 and Windows 11, including Home editions and domain-joined PCs.
Track Failed Sign-In Attempts with Audit Policy in Windows 10/11
Difficulty: Intermediate | Time Required: 15 minutes
Failed sign-in attempts can be an early warning sign of a forgotten password, a misconfigured service, a saved credential problem, Remote Desktop probing, or even an attempted...