How To Check Computer Login History In Windows 11

Did you know that you can easily check the login history on your Windows 11 computer? In this guide, we will show you how to do it using the built-in Event Viewer and other methods.

To check your computer’s login history, one method is through the Event Viewer. You can access the Event Viewer by searching for it in the Start Menu or by pressing Win + R and typing “eventvwr.msc” and clicking Ok.

In the Event Viewer interface, navigate to Windows Logs > Security and look for Event ID 4624. This particular event ID indicates user login, and by selecting a specific event and clicking Details, you can view information about the user login.

If you want to filter the information to only show Event ID 4624, right-click on Custom View in the Event Viewer, select Create Custom View, choose Security for By Log, and replace with 4624.

Alternatively, you can enable the Logon Auditing Policy to track user login history. Open the Group Policy Editor from the Start Menu, navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy, and double-click on Audit logon events. Check both Success and Failure, then restart your computer to start tracking user login history.

Another method for viewing login history is by using a third-party utility called WinLogOnView.

With these methods at your disposal, you can easily keep track of the login history on your Windows 11 computer, ensuring the security and accountability of user activities.

Using Event Viewer to Check Computer Login History in Windows 11

The Event Viewer in Windows 11 provides a powerful tool for checking the login history on your computer. Follow these steps to access the Event Viewer and find the relevant login events.

To begin, open the Event Viewer by either searching for it in the Start Menu or pressing Win + R, typing “eventvwr.msc,” and clicking OK. Once the Event Viewer is open, navigate to Windows Logs > Security. In the Security log, you will find various events related to system security, including login events.

Look for the Event ID 4624, which indicates a successful user login. This event ID is specifically associated with user logins and will help you identify the relevant events. To view the details of a specific login event, simply select it and click on the Details tab.

If you want to filter the login events to only show Event ID 4624, you can create a custom view. Right-click on Custom Views in the Event Viewer, select Create Custom View, choose Security for “By Log,” and replace “” with 4624. This will create a custom view that only displays the login events you are interested in.

Additionally, you can enable the Logon Auditing Policy to track user login history. To do this, open the Group Policy Editor from the Start Menu and navigate to Computer Configuration > Windows Settings > Security Settings > Local Policies > Audit Policy. Double-click on Audit logon events, check both Success and Failure, and click Apply. Remember to restart your computer to start tracking user login history.

Alternatively, you can use a third-party utility called WinLogOnView to view login history. This utility provides another method for accessing and reviewing login events on your Windows 11 computer.

Meet the Author

Abdul Rahim has been working in Information Technology for over two decades. Learn how Abdul got his start as a Tech Blogger , and why he decided to start this Software blog. If you want to send Abdul a quick message, then visit his contact page here.