Skip to content
Skip to main content
First Response & Preservation Technical Explainer

Could logging out destroy useful evidence?

Yes. Logging out can end a live session, close its processes and remove the easiest view of account, application and remote-system activity.

That does not mean a logout is never justified. It means the decision should be treated as a change to the evidence, not as harmless tidying before seizure.

First establish what “log out” will end

The same label can describe quite different actions:

Website or applicationEnds one account sessionThe computer remains running, but the authenticated view and temporary application state may disappear.
Computer userEnds the operating-system sessionApplications and user processes may close, taking unsaved work and live connections with them.
Remote desktopSign out is not the same as disconnectA disconnect may leave the remote session running; a sign-out can end its processes and delete the session.

A prompt such as Sign out everywhere, End session or Close apps and sign out is therefore evidence in its own right. Record the wording and affected account or device before choosing anything.

Current Microsoft Remote Desktop behaviour - checked 27 September 2026

Microsoft documents that tsdiscon disconnects a Remote Desktop Session Host session while its applications keep running for reconnection. By contrast, logoff ends the session's processes and deletes that session. These are Windows Remote Desktop Session Host behaviours, not a universal rule for every remote-access product.

Why the live session may matter

A login session is the continuing authorised state that follows authentication. While it remains open, it may expose:

  • the account and service in use;
  • open files, drafts and unsaved work;
  • browser tabs and cloud applications;
  • active network shares or remote desktops;
  • security notices and linked-device information; and
  • temporary credentials or session material needed to explain later activity.

Logging out may not erase every underlying record. Provider, server and device logs may still show authentication and activity. The loss is the live relationship between those records and the state visible now.

BeforeLive session visibleAccount, applications, prompts and connections can be recorded together.
ActionLogout ends accessApplications or remote processes may close and new audit events may be created.
AfterHistorical records remainThey may show that logout occurred without recreating every window, draft or temporary connection.

Preserve enough to explain the decision

Before logout, record the device, account, service, session, open applications, connected systems, visible prompts and time. Preserve the full workspace and any warning about unsaved work. If containment is required, consider whether a narrower control can address the specific risk without ending every session.

Where urgent harm makes logout necessary, record who authorised it, why delay was unacceptable, the exact option selected and what changed. That gives later investigators a reliable boundary between original state and response activity.

Reference: FRP-081First Response & Preservation