Endpoint configuration · GraphQL type

LogonSessionWindows type

MS Windows O/S specific logon session information.

Fields

Field Name Description
logonId - Luid! A locally unique identifier (LUID) that identifies a logon session.
logonDomain - String! The name of the domain used to authenticate the owner of the logon session.
authenticationPackage - String! The name of the authentication package used to authenticate the owner of the logon session.
logonType - WindowsLogonType How the session was established, such as interactive, network, or remote interactive. See WindowsLogonType.
logonSid - String! Security identifier (SID) of the user logged in, a variable-length string that uniquely identifies users or groups in the MS Windows O/S.
logonServer - String! The name of the server used to authenticate the owner of the logon session.
dnsDomainName - String! Contains the DNS name for the owner of the logon session.
logonScript - String! The script used for logging on.
profilePath - String! Contains the path to the user's profile.
homeDirectory - String! The home directory for the logon session.
homeDirectoryDrive - String! Drive location of the home directory of the logon session.

Used by

  • LogonSession type: A user logon session observed on an Endpoint, identified by the username and the time the session started.
  • LogonSessionOsSpecific union: OS-specific logon session union type.

Example

Example

{
  "logonId": "999",
  "logonDomain": "abc123",
  "authenticationPackage": "xyz789",
  "logonType": "UNDEFINED",
  "logonSid": "abc123",
  "logonServer": "xyz789",
  "dnsDomainName": "xyz789",
  "logonScript": "xyz789",
  "profilePath": "abc123",
  "homeDirectory": "xyz789",
  "homeDirectoryDrive": "xyz789"
}